Man-in-the-Middle Attack Vulnerability in mH-DEVELOPER Smart Home Module
CVE-2026-82929
6.3MEDIUM
What is CVE-2026-82929?
The mH-DEVELOPER Smart Home Module contains a vulnerability where it employs identical hard-coded SSH host keys across all devices, lacking unique keys for each unit. This creates a security risk whereby an attacker can extract these keys from the module's firmware and set up a malicious SSH server. Clients connecting to this rogue server may unknowingly trust it, making them susceptible to man-in-the-middle attacks and credential interception. The vulnerability was addressed and resolved in version 3.0.30.
Affected Version(s)
mH-DEVELOPER 0 < 3.0.30
