Security Flaw in mH-DEVELOPER Smart Home Module Exposes Root Access
CVE-2026-82928

7.7HIGH

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82928?

The mH-DEVELOPER smart home module is vulnerable due to a hardcoded SSH public key located in /root/.ssh/authorized_keys, which can act as a backdoor. This setup allows root login via key authentication, leading to unauthorized access by individuals possessing the corresponding private key. Attackers can exploit this vulnerability to gain root shell access on any affected device, allowing for complete control over the system. Notably, the hardcoded key can only be removed by remounting the file system, and it remains present even after a factory reset. While the vendor indicated that this feature was meant strictly for service purposes, it poses a serious risk to the device's security.

Affected Version(s)

mH-DEVELOPER 0 < 3.0.30

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Chudzik (CERT.PL)
.