CVE-2026-22885Disclosure

LOWCVSS 3.7 · LOW

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: High priority (within 72h)

NVD description

A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

2.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-30: 2Exploit Tool / Code · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 204-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Mr.Rabbit@01ra66it
    Disclosure

    【EnOcean SmartServerの欠陥で、建物管理システムが遠隔侵害可能に】 SecurityWeekによると、Clarotyは EnOcean SmartServer に CVE-2026-22885 と CVE-2026-20761 を発見し、インターネット露出デバイスに対してメモリ保護回避、メモリ漏えい、任意コマンド実行が可能だと報告しました。対象はスマートビル、工場、データセンター向けの building automation ゲートウェイです。 この種の機器は“ITでもOTでもない境界装置”として見逃されがちですが、実際には施設制御、環境制御、保守導線のハブです。Linuxベースのデバイスを root で乗っ取られると、監視・制御・足場化のすべてが危険になります。 ビル管理・工場・データセンター運用では、クラウド接続や公開保守経路を含めて SmartServer の露出確認を急ぐべきです。 #ICS #OTSecurity #BuildingAutomation #EnOcean #RCE #BlueTeam https://www.securityweek.com/enocean-smartserver-flaws-expose-buildings-to-remote-hacking/

    Post summary

    EnOcean SmartServer is vulnerable to CVE‑2026‑22885 and CVE‑2026‑20761, allowing attackers to bypass memory protections, cause memory leaks, and execute arbitrary commands over the internet, posing a serious threat to building automation systems.

    00000140
    3.5K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Critical flaws CVE-2026-20761 and CVE-2026-22885 in EnOcean SmartServer ≤4.60.009 enable remote takeover of building management systems, fixed in v4.60.023. https://threatcluster.io/cluster/critical-vulnerabilities-in-enocean-smartserver-expose-build-92c87164

    Post summary

    The article reports two critical CVEs in EnOcean SmartServer versions up to 4.60.009 that enable remote takeover of building management systems and notes the issue is resolved in v4.60.023.

    0000024
    172 followersView on X

Explore more