CVE-2026-82932
MEDIUM
5,3
Source: [email protected]
Attack Vector: adjacent
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
923
Improper Restriction of Communication Channel to Intended Endpoints
IncompleteCommon Consequences
Security Scopes Affected:
Integrity
Confidentiality
Potential Impacts:
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Web Server
https://cert.pl/posts/2026/09/CVE-2026-82928/
https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html