mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.
This issue was fixed in versionĀ 3.0.30
This issue was fixed in versionĀ 3.0.30
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 28 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in versionĀ 3.0.30 | |
| Title | Undocumented access path in mH-DEVELOPER | |
| First Time appeared |
F F Filipowski
F F Filipowski mh-developer |
|
| Weaknesses | CWE-1242 | |
| CPEs | cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:* | |
| Vendors & Products |
F F Filipowski
F F Filipowski mh-developer |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-09-28T12:11:40.726Z
Reserved: 2026-08-31T12:23:36.734Z
Link: CVE-2026-82928
No data.
Status : Received
Published: 2026-09-28T13:17:23.253
Modified: 2026-09-28T13:17:23.253
Link: CVE-2026-82928
No data.
OpenCVE Enrichment
Updated: 2026-09-28T13:30:18Z
Weaknesses