🔐 CVE Alert

CVE-2026-82935

UNKNOWN 0.0

Use of End-of-Life components in mH-DEVELOPER

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device. Vulnerable components were updated or hardened, if update was not possible in version 3.0.30

CWE CWE-1104
Vendor f&f filipowski
Product mh-developer
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for f&f filipowski mh-developer

Be the first to know when new unknown vulnerabilities affecting f&f filipowski mh-developer are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

F&F Filipowski / mH-DEVELOPER
0 < 3.0.30

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/posts/2026/09/CVE-2026-82928/ fif.com.pl: https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html

Credits

Krzysztof Chudzik (CERT.PL)