CVE-2026-82929
Received
Received - Intake
Hard-Coded SSH Host Keys in mH-DEVELOPER Smart Home Module
Vulnerability report for CVE-2026-82929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-28
Last updated on: 2026-09-28
Assigner: CERT.PL
Description
Description
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in versionΒ 3.0.30
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mh-developer | smart_home_module | 3.0.30 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-321 | The product uses a hard-coded, unchangeable cryptographic key. |