Man-in-the-Middle Attack Vulnerability in mH-DEVELOPER Smart Home Module
CVE-2026-82929

6.3MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82929?

The mH-DEVELOPER Smart Home Module contains a vulnerability where it employs identical hard-coded SSH host keys across all devices, lacking unique keys for each unit. This creates a security risk whereby an attacker can extract these keys from the module's firmware and set up a malicious SSH server. Clients connecting to this rogue server may unknowingly trust it, making them susceptible to man-in-the-middle attacks and credential interception. The vulnerability was addressed and resolved in version 3.0.30.

Affected Version(s)

mH-DEVELOPER 0 < 3.0.30

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Chudzik (CERT.PL)
.