This issue was fixed in versionĀ 3.0.30
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in versionĀ 3.0.30 | |
| Title | Undocumented access path in mH-DEVELOPER | |
| First Time appeared |
F F Filipowski
F F Filipowski mh-developer |
|
| Weaknesses | CWE-1242 | |
| CPEs | cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
F F Filipowski
F F Filipowski mh-developer |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-28T12:11:40.726Z
Reserved: 2026-08-31T12:23:36.734Z
Link: CVE-2026-82928
No data.
Status : Received
Published: 2026-09-28T13:17:23.253
Modified: 2026-09-28T13:17:23.253
Link: CVE-2026-82928
No data.
OpenCVE Enrichment
Updated: 2026-09-28T13:30:18Z
-
CWE-1242
Inclusion of Undocumented Features or Chicken Bits