CVE-2026-82932
Received Received - Intake

mH-DEVELOPER Smart Home Module Firewall Bypass

Vulnerability report for CVE-2026-82932, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in versionΒ 3.0.30

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mh-developer smart_home_module 3.0.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-923 The product establishes a communication channel to (or from) an endpoint for privileged or protected operations, but it does not properly ensure that it is communicating with the correct endpoint.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The mH-DEVELOPER smart home module fails to load firewall rules at startup. This exposes all listening services like SSH, HTTP, WebSocket, and Node-RED on the local network without any access restrictions. Any device on the same network can access these services directly.

Detection Guidance

Check if firewall rules are loaded by running 'iptables -L' or 'ufw status' on Linux. Verify listening services with 'netstat -tuln' or 'ss -tuln'. Test remote access to services like SSH (port 22) or HTTP (port 80) from another device on the same network.

Impact Analysis

Unauthorized users on your local network could gain access to your smart home services. This may allow them to control devices, steal data, or launch further attacks on your network. The lack of firewall rules means no protection against such intrusions.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating privacy regulations like GDPR or HIPAA. Exposure of services without access control may result in non-compliance with data protection requirements.

Mitigation Strategies

Update the mH-DEVELOPER smart home module to version 3.0.30 or later. Manually configure a firewall to restrict access to exposed services. Disable unnecessary services like SSH or HTTP if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82932. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart