🔐 CVE Alert

CVE-2026-82930

UNKNOWN 0.0

Missing Authentication in mH-DEVELOPER

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in version 3.0.30

CWE CWE-306
Vendor f&f filipowski
Product mh-developer
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for f&f filipowski mh-developer

Be the first to know when new unknown vulnerabilities affecting f&f filipowski mh-developer are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

F&F Filipowski / mH-DEVELOPER
0 < 3.0.30

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/09/CVE-2026-82928/ fif.com.pl: https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html

Credits

Krzysztof Chudzik (CERT.PL)