DFIR Radar[verified]@DFIR_RadarPatch
The post announces CVE-2026-20761, a remote code execution flaw on EnOcean SmartServer IoT platforms, and urges users to update to version 4.60.023 immediately.
Mr.Rabbit[verified]@01ra66itDisclosure
EnOcean SmartServer devices exhibit memory protection bypass, leaks, and arbitrary command execution (CVE‑2026‑22885/20761), enabling remote exploitation of building automation gateways, and security teams should urgently assess exposure and apply vendor fixes.
ThreatCluster[verified]@threatclusterPatch
The message announces critical flaws CVE-2026-20761 and CVE-2026-22885 in EnOcean SmartServer, highlights remote takeover risk, and states that a patch (v4.60.023) has fixed the issue.
CVETodo[verified]@CveTodoDisclosure
Alert reports CVE‑2026‑20761 in EnOcean SmartServer enables remote code execution via crafted LON IP‑852 messages. No PoC, exploit, or patch is discussed.
The Hacker Wire@TheHackerWireDisclosure
EnOcean SmartServer IoT versions 4.60.009 and earlier are vulnerable to remote attacks via specially crafted LON IP-852 management messages, with no PoC, patches, or evidence of active exploitation disclosed.