Authorization Bypass in mH-DEVELOPER Smart Home Module
CVE-2026-82930

6.4MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82930?

The mH-DEVELOPER Smart Home Module contains a significant vulnerability due to inadequate token validation in its authorization middleware. As a result, all HTTP API and WebSocket endpoints are exposed to unauthorized access, allowing unauthenticated attackers on the local area network to query sensitive system information and issue raw control commands. This flaw can lead to unauthorized manipulation of building automation systems, posing a serious security risk for smart home environments. Users are advised to upgrade to version 3.0.30 or later to mitigate this issue.

Affected Version(s)

mH-DEVELOPER 0 < 3.0.30

References

CVSS V4

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Chudzik (CERT.PL)
.