mH-DEVELOPER 智能家居模块在所有设备上使用相同的硬编码 SSH 主机密钥,且未进行针对每个设备的密钥生成。攻击者若从固件中提取这些密钥,便可搭建一个伪装的 SSH 服务器,客户端会在未收到任何警告的情况下信任该服务器,从而实施中间人攻击并截获凭证。 该问题已在版本 3.0.30 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F&F Filipowski | mH-DEVELOPER | 0 ~ 3.0.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82928 | 7.7 HIGH | Undocumented access path in mH-DEVELOPER |
| CVE-2026-82935 | 6.9 MEDIUM | Use of End-of-Life components in mH-DEVELOPER |
| CVE-2026-82930 | 6.4 MEDIUM | Missing Authentication in mH-DEVELOPER |
| CVE-2026-82933 | 6.0 MEDIUM | Cleartext Transmission of Sensitive Information in mH-DEVELOPER |
| CVE-2026-82936 | 5.9 MEDIUM | Denial of Service in mH-DEVELOPER |
| CVE-2026-82932 | 5.3 MEDIUM | Missing Firewall Configuration in mH-DEVELOPER |
No comments yet