CVE-2026-20761

8.1

EnOcean Edge Inc · SmartServer IoT

A command injection vulnerability in EnOcean SmartServer IoT allows unauthenticated remote attackers to execute arbitrary OS commands via crafted LON IP-852 management messages.

Executive summary

A critical command injection vulnerability in EnOcean SmartServer IoT can be exploited by remote, unauthenticated attackers to gain full system control.

Vulnerability

This vulnerability, classified as CWE-77, allows an unauthenticated remote attacker to send malicious LON IP-852 management messages to the device. This interaction triggers arbitrary operating system command execution with elevated privileges on the target hardware.

Business impact

The ability to execute arbitrary commands on an IoT gateway poses a severe risk to operational technology environments. A successful exploit could lead to complete device takeover, unauthorized access to internal network segments, or the disruption of critical automation processes, justifying the high CVSS score of 8.1.

Remediation

Immediate Action: Update the SmartServer platform software to version 4.60.023 or later as specified in the official release notes.

Proactive Monitoring: Monitor network traffic for unusual IP-852 management packets and audit device logs for unexpected process execution or unauthorized configuration changes.

Compensating Controls: Restrict access to the LON IP-852 management interface at the network perimeter to ensure only authorized management stations can communicate with the device.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote command execution and the critical nature of IoT gateway infrastructure, administrators should prioritize updating to firmware version 4.60.023 immediately. If an immediate update is not feasible, ensure the device is isolated from the public internet and restricted to trusted management segments to mitigate the risk of unauthorized exploitation.

Sources

Originally found and disclosed by Amir Zaltzman of Claroty Team82 reported these vulnerabilities to CISA., per the CVE Program record.