All CVEs
Vulnerability intelligence

CVE-2026-20761

CWE-77

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

CVSS Score
8.1
High
EPSS — Exploit Probability
0.9%
Riskier than 55% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Apr 30, 2026 · latest Apr 30, 2026

Coverage timeline