VORANT. Threat Intelligence Research Sign in Create a free account

CERT Polska details flaws in mH-DEVELOPER smart home hub

routine vulnerability infrastructure

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT Polska disclosed multiple vulnerabilities, including a hardcoded root SSH backdoor, in F&F Filipowski mH-DEVELOPER smart home devices, fixed in version 3.0.30.

CERT Polska researcher Krzysztof Chudzik discovered a series of vulnerabilities in F&F Filipowski mH-DEVELOPER smart home modules during independent research (assisted by an LLM, manually verified and coordinated with the vendor). The most severe issue, CVE-2026-82928, is a hardcoded SSH public key in root's authorized_keys file that allows anyone with the matching private key to obtain a root shell on any affected device — the key cannot be removed without remounting the filesystem and survives a factory reset, effectively acting as a permanent backdoor. A related flaw, CVE-2026-82929, involves identical hardcoded SSH host keys shared across all devices, enabling rogue SSH server man-in-the-middle attacks against clients.

Several additional issues compound the risk: CVE-2026-82930 describes missing authorization on all HTTP API and WebSocket endpoints, letting any unauthenticated LAN attacker query system information and send raw control commands to building automation devices. CVE-2026-82932 notes the device loads no firewall rules at startup, exposing SSH, HTTP, WebSocket, and Node-RED services to any LAN client. CVE-2026-82933 covers unencrypted HTTP traffic that exposes credentials, tokens, and commands to network interception. CVE-2026-82935 flags end-of-life Debian 8 and Node.js 17.0.1 in production firmware, exposing devices to unpatched known vulnerabilities. Finally, CVE-2026-82936 is a denial-of-service issue where an oversized (250MB) JSON/URL-encoded body can exhaust device memory and crash the fh-node process — made trivially exploitable by the unauthenticated API access from CVE-2026-82930.

All issues were fixed in mH-DEVELOPER version 3.0.30. No in-the-wild exploitation is reported; this is coordinated vulnerability disclosure research. Defenders operating these smart home/building automation modules should update to 3.0.30 immediately, verify SSH keys are regenerated (not merely relying on firmware update to clear the backdoor key without filesystem remount), enforce network segmentation for LAN-exposed OT/IoT devices, and monitor for unauthorized SSH or unauthenticated API access on affected units.

Mentioned in this report

Vulnerabilities CVE-2026-82928CVE-2026-82929CVE-2026-82930CVE-2026-82932CVE-2026-82933CVE-2026-82935CVE-2026-82936

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-82928

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,126 reports from 154 sources, 2,670 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs