CVE-2026-82936
Received Received - Intake

Denial of Service in mH-DEVELOPER Smart Home Module

Vulnerability report for CVE-2026-82936, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: CERT.PL

Description

mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack. This issue was fixed in versionΒ 3.0.30

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mh-developer smart_home_module 3.0.30

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Denial of Service issue in the mH-DEVELOPER smart home module caused by uncontrolled resource consumption. The Express bodyParser is set to allow up to 250 MB for JSON and URL-encoded request bodies. An authenticated attacker on the local network can send oversized requests, exhausting RAM and crashing the fh-node process, leading to service disruption.

Detection Guidance

Monitor for sudden crashes of the fh-node process or out-of-memory errors in system logs. Check for unusually large incoming requests on the smart home module's network interfaces. Use tools like netstat or tcpdump to inspect traffic patterns for unusually large payloads.

Impact Analysis

This vulnerability allows any local network user to crash the smart home module by sending large requests, disrupting its functionality. Since CVE-2026-82930 enables unauthenticated access to all endpoints, even unauthenticated users on the LAN can exploit this issue, causing outages or requiring manual restarts.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing service disruptions due to Denial of Service attacks. Unplanned downtime may lead to unauthorized access risks or data processing interruptions, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade the mH-DEVELOPER smart home module to version 3.0.30 or later. If upgrading is not immediately possible, restrict network access to the module to trusted users only. Disable unauthenticated endpoint access by applying the fix for CVE-2026-82930.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82936. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart