mH-DEVELOPER 智能家居模块的 Web 界面和 API 通信通过未加密的 HTTP 进行传输。密码、身份验证令牌及设备控制指令均以明文形式传输。位于同一网络中的攻击者可拦截这些流量,窃取凭据和令牌,并劫持用户会话。 该问题已在 3.0.30 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F&F Filipowski | mH-DEVELOPER | 0 ~ 3.0.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82928 | 7.7 HIGH | Undocumented access path in mH-DEVELOPER |
| CVE-2026-82935 | 6.9 MEDIUM | Use of End-of-Life components in mH-DEVELOPER |
| CVE-2026-82930 | 6.4 MEDIUM | Missing Authentication in mH-DEVELOPER |
| CVE-2026-82929 | 6.3 MEDIUM | Use of Shared Cryptographic Key in mH-DEVELOPER |
| CVE-2026-82936 | 5.9 MEDIUM | Denial of Service in mH-DEVELOPER |
| CVE-2026-82932 | 5.3 MEDIUM | Missing Firewall Configuration in mH-DEVELOPER |
No comments yet