Security Flaw in mH-DEVELOPER Smart Home Module Exposes Root Access
CVE-2026-82928
7.7HIGH
What is CVE-2026-82928?
The mH-DEVELOPER smart home module is vulnerable due to a hardcoded SSH public key located in /root/.ssh/authorized_keys, which can act as a backdoor. This setup allows root login via key authentication, leading to unauthorized access by individuals possessing the corresponding private key. Attackers can exploit this vulnerability to gain root shell access on any affected device, allowing for complete control over the system. Notably, the hardcoded key can only be removed by remounting the file system, and it remains present even after a factory reset. While the vendor indicated that this feature was meant strictly for service purposes, it poses a serious risk to the device's security.
Affected Version(s)
mH-DEVELOPER 0 < 3.0.30
