CVE-2026-82928 Details
Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
A hardcoded SSH public key has been found in the mH-DEVELOPER smart home module by F&F Filipowski, specifically in the authorized_keys file for the root user. This key allows root login via SSH key authentication, creating a potential backdoor. The SSH daemon, which enables this access, starts automatically and can’t be disabled. An attacker with the corresponding private key can gain a root shell on the device, leading to full system compromise. This vulnerability affects all versions of the mH-DEVELOPER module prior to 3.0.30.
Users can update to version 3.0.30 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-82928/ | [email protected] | AdvisoryBundleRemedy |
| https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1242 | Inclusion of Undocumented Features or Chicken Bits | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| F&F Filipowski mH-DEVELOPER | < 3.0.30 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion