This issue was fixed in version 3.0.30
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30 | |
| Title | Undocumented access path in mH-DEVELOPER | |
| First Time appeared |
F F Filipowski
F F Filipowski mh-developer |
|
| Weaknesses | CWE-1242 | |
| CPEs | cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
F F Filipowski
F F Filipowski mh-developer |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-28T16:32:28.919Z
Reserved: 2026-08-31T12:23:36.734Z
Link: CVE-2026-82928
Updated: 2026-09-28T16:22:36.791Z
Status : Deferred
Published: 2026-09-28T13:17:23.253
Modified: 2026-09-28T17:17:50.883
Link: CVE-2026-82928
No data.
OpenCVE Enrichment
Updated: 2026-09-28T17:15:04Z
-
CWE-1242
Inclusion of Undocumented Features or Chicken Bits