CVE-2026-22885: Enocean Edge Inc Smartserver IoT

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

Affected products

Published 2026-02-20. Last modified 2026-06-17.