VYPR

Smartserver

by Enocean

CVEs (3)

  • CVE-2026-20761HigFeb 20, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in arbitrary OS command execution on the device.

  • CVE-2026-22885LowFeb 20, 2026
    risk 0.24cvss 3.7epss 0.00

    A vulnerability exists in EnOcean SmartServer IoT version 4.60.009 and prior, which would allow remote attackers, in the LON IP-852 management messages, to send specially crafted IP-852 messages resulting in a memory leak from the program's memory.

  • CVE-2022-3089Feb 13, 2023
    risk 0.00cvss epss 0.00

    Echelon SmartServer 2.2 with i.LON Vision 2.2 stores cleartext credentials in a file, which could allow an attacker to obtain cleartext usernames and passwords of the SmartServer. If the attacker obtains the file, then the credentials could be used to control the web user interface and file transfer protocol (FTP) server.