mH-DEVELOPER 智能家居模块存在拒绝服务(DoS)漏洞,源于不可控的资源消耗。该模块使用的 Express bodyParser 将 JSON 和 URL 编码请求体的大小限制设置为 250 MB。局域网内的已认证攻击者可发送大型请求体,耗尽随机存取存储器(RAM)中的缓冲区,导致内存溢出(Out-of-Memory)并引发 fh-node 进程崩溃,从而造成拒绝服务。攻击能否成功取决于设备当前的内存使用情况,而攻击者无法完全控制这一因素。 严重的是,由于 CVE-2026-82930 漏洞的存在,所有端
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F&F Filipowski | mH-DEVELOPER | 0 ~ 3.0.30 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82928 | 7.7 HIGH | Undocumented access path in mH-DEVELOPER |
| CVE-2026-82935 | 6.9 MEDIUM | Use of End-of-Life components in mH-DEVELOPER |
| CVE-2026-82930 | 6.4 MEDIUM | Missing Authentication in mH-DEVELOPER |
| CVE-2026-82929 | 6.3 MEDIUM | Use of Shared Cryptographic Key in mH-DEVELOPER |
| CVE-2026-82933 | 6.0 MEDIUM | Cleartext Transmission of Sensitive Information in mH-DEVELOPER |
| CVE-2026-82932 | 5.3 MEDIUM | Missing Firewall Configuration in mH-DEVELOPER |
No comments yet