CVE-2026-82935
Use of End-of-Life components in mH-DEVELOPER
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device. Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
| CWE | CWE-1104 |
| Vendor | f&f filipowski |
| Product | mh-developer |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for f&f filipowski mh-developer
Be the first to know when new unknown vulnerabilities affecting f&f filipowski mh-developer are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
F&F Filipowski / mH-DEVELOPER
0 < 3.0.30
References
Credits
Krzysztof Chudzik (CERT.PL)