CVE-2026-82933 Details
Description
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in version 3.0.30
A vulnerability exists in the F&F Filipowski mH-DEVELOPER smart home module due to the transmission of web interface and API traffic over unencrypted HTTP. This flaw affects all versions prior to 3.0.30. As a result, passwords, authentication tokens, and device commands are sent in cleartext, allowing an attacker on the same network to intercept this information, steal credentials and tokens, and hijack user sessions.
Users can update to version 3.0.30 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-82928/ | [email protected] | AdvisoryBundleRemedy |
| https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html | [email protected] | ProductVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| F&F Filipowski mH-DEVELOPER | < 3.0.30 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion