CVE-2026-82936 Details
Description
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack. This issue was fixed in version 3.0.30
A denial-of-service vulnerability has been identified in the F&F Filipowski mH-DEVELOPER smart home module, all versions prior to 3.0.30. The issue arises from uncontrolled resource consumption, as the Express bodyParser allows JSON and URL-encoded request bodies of up to 250 MB. An authenticated attacker on the local area network can exploit this by sending large request bodies that consume available RAM, leading to out-of-memory conditions that crash the fh-node process. This vulnerability is exacerbated by another issue (CVE-2026-82930) that allows unauthenticated access to all endpoints, enabling any user on the LAN to perform the attack.
Users can update to version 3.0.30 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/09/CVE-2026-82928/ | [email protected] | BundleTechnical Description |
| https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| F&F Filipowski mH-DEVELOPER | < 3.0.30 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion