Authorization Bypass in mH-DEVELOPER Smart Home Module
CVE-2026-82930
6.4MEDIUM
What is CVE-2026-82930?
The mH-DEVELOPER Smart Home Module contains a significant vulnerability due to inadequate token validation in its authorization middleware. As a result, all HTTP API and WebSocket endpoints are exposed to unauthorized access, allowing unauthenticated attackers on the local area network to query sensitive system information and issue raw control commands. This flaw can lead to unauthorized manipulation of building automation systems, posing a serious security risk for smart home environments. Users are advised to upgrade to version 3.0.30 or later to mitigate this issue.
Affected Version(s)
mH-DEVELOPER 0 < 3.0.30
