CVE-2026-82929
Received Received - Intake

Hard-Coded SSH Host Keys in mH-DEVELOPER Smart Home Module

Vulnerability report for CVE-2026-82929, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This issue was fixed in versionΒ 3.0.30

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mh-developer smart_home_module 3.0.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The mH-DEVELOPER smart home module uses identical hard-coded SSH host keys across all devices. This means every device shares the same private and public SSH keys. An attacker can extract these keys from the firmware and set up a malicious SSH server that devices will trust, allowing them to intercept communications and steal credentials without raising any warnings.

Detection Guidance

Check for duplicate SSH host keys across devices by comparing key fingerprints. Use commands like 'ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub' on each device and compare outputs. Look for identical keys which indicate the vulnerability.

Impact Analysis

If you use the affected mH-DEVELOPER smart home module, an attacker could intercept your SSH communications, steal login credentials, or manipulate data transmitted between your device and other systems. This could lead to unauthorized access to your smart home network or sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating privacy requirements under GDPR and HIPAA. Organizations using this module may fail to meet data protection standards, risking legal penalties and reputational damage.

Mitigation Strategies

Upgrade the mH-DEVELOPER smart home module to version 3.0.30 or later. Regenerate SSH host keys on all affected devices using 'ssh-keygen -t rsa -f /etc/ssh/ssh_host_rsa_key' and restart SSH services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82929. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart