CVE-2026-82935 Details
Description
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device. Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
A vulnerability exists in the F&F Filipowski mH-DEVELOPER smart home module, all versions prior to 3.0.30, due to the use of outdated and unsupported software, including Debian 8 and Node.js version 17.0.1, in its production firmware. This reliance on unmaintained components exposes the device to publicly known vulnerabilities that will not receive security updates. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial-of-service condition on the device.
This vulnerability was fixed in version 3.0.30.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-82928/ | [email protected] | AdvisoryBundleRemedy |
| https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1104 | Use of Unmaintained Third Party Components | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| F&F Filipowski mH-DEVELOPER | < 3.0.30 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion