CVE-2026-82928

Published: Set 28, 2026 Last Modified: Set 28, 2026
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,7
Attack Vector: adjacent
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A

Description

AI Translation Available

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.

This issue was fixed in version 3.0.30

1242

Inclusion of Undocumented Features or Chicken Bits

Incomplete
Common Consequences
Security Scopes Affected:
Confidentiality Integrity Availability Access Control
Potential Impacts:
Modify Memory Read Memory Execute Unauthorized Code Or Commands Gain Privileges Or Assume Identity Bypass Protection Mechanism
Applicable Platforms
Technologies: Not Technology-Specific, ICS/OT
View CWE Details
https://cert.pl/posts/2026/09/CVE-2026-82928/
https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html