
Two critical vulnerabilities in EnOcean SmartServer IoT (CVE-2026-20761, CVE-2026-22885) allow remote, unauthenticated attackers to gain root access to building management system controllers via crafted IP-852 UDP packets. Analysis, MITRE ATT&CK mapping, and defensive recommendations.