CVE-2026-82930
Received Received - Intake

Unauthenticated API Access in mH-DEVELOPER Smart Home Module

Vulnerability report for CVE-2026-82930, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in versionΒ 3.0.30

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mh-developer smart_home_module 3.0.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The mH-DEVELOPER smart home module has an authorization flaw where its middleware does not validate tokens. This allows unauthenticated attackers on the local network to access HTTP API and WebSocket endpoints without authentication. They can then retrieve system details and send unauthorized control commands to manipulate connected building automation devices.

Detection Guidance

Check if unauthenticated access is possible by sending HTTP requests to the smart home module's API endpoints without a token. Use tools like curl to query endpoints such as /api/system or /api/devices. If responses are received without authentication, the system is vulnerable.

Impact Analysis

An attacker could gain unauthorized access to your smart home system, steal sensitive information, or manipulate devices like thermostats, lights, or security systems. This could lead to privacy breaches, property damage, or safety risks depending on the connected devices.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR or HIPAA by exposing personal or health-related data. Unauthorized access to smart home systems may result in non-compliance with privacy and security controls mandated by these regulations.

Mitigation Strategies

Upgrade the mH-DEVELOPER smart home module to version 3.0.30 or later. If an upgrade is not immediately possible, restrict network access to the module by blocking unauthorized LAN connections or using a firewall to limit access to trusted IPs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82930. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart