mH-DEVELOPER 智能家居模块的生产固件中捆绑了已停止支持(End-of-Life)的 Debian 8 系统以及 Node.js v17.0.1 运行时环境。这使得该设备暴露于众多公开的已知漏洞中,且这些漏洞将不再获得安全补丁。攻击者可利用这些已知缺陷,在设备上执行任意代码、访问敏感数据,或导致设备发生服务中断(DoS)。 在版本 3.0.30 中,相关易受攻击的组件已得到更新或加固;若某些组件无法更新,则采取了相应的加固措施。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F&F Filipowski | mH-DEVELOPER | 0 ~ 3.0.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82928 | 7.7 HIGH | Undocumented access path in mH-DEVELOPER |
| CVE-2026-82930 | 6.4 MEDIUM | Missing Authentication in mH-DEVELOPER |
| CVE-2026-82929 | 6.3 MEDIUM | Use of Shared Cryptographic Key in mH-DEVELOPER |
| CVE-2026-82933 | 6.0 MEDIUM | Cleartext Transmission of Sensitive Information in mH-DEVELOPER |
| CVE-2026-82936 | 5.9 MEDIUM | Denial of Service in mH-DEVELOPER |
| CVE-2026-82932 | 5.3 MEDIUM | Missing Firewall Configuration in mH-DEVELOPER |
No comments yet