CVE-2026-20761: Enocean Edge Inc Smartserver IoT
High severity, CVSS 8.1. EPSS: 0.9% chance of exploitation in the next 30 days.
A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.
Affected products
- Enocean Edge Inc Smartserver IoT: up to and including 4.60.009
Published 2026-02-20. Last modified 2026-06-17.