CVE-2026-82929
Use of Shared Cryptographic Key in mH-DEVELOPER
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This issue was fixed in version 3.0.30
| CWE | CWE-321 |
| Vendor | f&f filipowski |
| Product | mh-developer |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for f&f filipowski mh-developer
Be the first to know when new unknown vulnerabilities affecting f&f filipowski mh-developer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
F&F Filipowski / mH-DEVELOPER
0 < 3.0.30
References
Credits
Krzysztof Chudzik (CERT.PL)