# CERT Polska details flaws in mH-DEVELOPER smart home hub

Published: 2026-09-28 · Severity: routine · Sectors: infrastructure
Canonical: https://vorant.io/reports/a768f52a-5f59-5657-b305-d81a6d903172/cert-polska-details-flaws-in-mh-developer-smart-home-hub

> CERT Polska disclosed multiple vulnerabilities, including a hardcoded root SSH backdoor, in F&F Filipowski mH-DEVELOPER smart home devices, fixed in version 3.0.30.

CERT Polska researcher Krzysztof Chudzik discovered a series of vulnerabilities in F&F Filipowski mH-DEVELOPER smart home modules during independent research (assisted by an LLM, manually verified and coordinated with the vendor). The most severe issue, CVE-2026-82928, is a hardcoded SSH public key in root's authorized_keys file that allows anyone with the matching private key to obtain a root shell on any affected device — the key cannot be removed without remounting the filesystem and survives a factory reset, effectively acting as a permanent backdoor. A related flaw, CVE-2026-82929, involves identical hardcoded SSH host keys shared across all devices, enabling rogue SSH server man-in-the-middle attacks against clients.

Several additional issues compound the risk: CVE-2026-82930 describes missing authorization on all HTTP API and WebSocket endpoints, letting any unauthenticated LAN attacker query system information and send raw control commands to building automation devices. CVE-2026-82932 notes the device loads no firewall rules at startup, exposing SSH, HTTP, WebSocket, and Node-RED services to any LAN client. CVE-2026-82933 covers unencrypted HTTP traffic that exposes credentials, tokens, and commands to network interception. CVE-2026-82935 flags end-of-life Debian 8 and Node.js 17.0.1 in production firmware, exposing devices to unpatched known vulnerabilities. Finally, CVE-2026-82936 is a denial-of-service issue where an oversized (250MB) JSON/URL-encoded body can exhaust device memory and crash the fh-node process — made trivially exploitable by the unauthenticated API access from CVE-2026-82930.

All issues were fixed in mH-DEVELOPER version 3.0.30. No in-the-wild exploitation is reported; this is coordinated vulnerability disclosure research. Defenders operating these smart home/building automation modules should update to 3.0.30 immediately, verify SSH keys are regenerated (not merely relying on firmware update to clear the backdoor key without filesystem remount), enforce network segmentation for LAN-exposed OT/IoT devices, and monitor for unauthorized SSH or unauthenticated API access on affected units.

## Mentioned in this report

- Vulnerabilities: CVE-2026-82928, CVE-2026-82929, CVE-2026-82930, CVE-2026-82932, CVE-2026-82933, CVE-2026-82935, CVE-2026-82936

Source reporting: https://cert.pl/en/posts/2026/09/CVE-2026-82928

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a768f52a-5f59-5657-b305-d81a6d903172/cert-polska-details-flaws-in-mh-developer-smart-home-hub.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
