Unencrypted HTTP Vulnerability in mH-DEVELOPER Smart Home Module
CVE-2026-82933

6MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82933?

The mH-DEVELOPER smart home module transmits its web interface and API communications over unencrypted HTTP, exposing sensitive information such as passwords, authentication tokens, and device commands. This lack of encryption allows an attacker on the same network to intercept the traffic, leading to potential credential theft and session hijacking. It is strongly recommended to update to version 3.0.30 or later to mitigate this security risk.

Affected Version(s)

mH-DEVELOPER 0 < 3.0.30

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Chudzik (CERT.PL)
.