Arbitrary Code Execution Vulnerability in mH-DEVELOPER Smart Home Module
CVE-2026-82935

6.9MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-82935?

The mH-DEVELOPER Smart Home Module is at risk due to its reliance on an end-of-life, unsupported Debian 8 operating system and Node.js runtime v17.0.1. These outdated components are susceptible to known vulnerabilities that will not be patched, potentially allowing attackers to execute arbitrary code, access sensitive information, or disrupt the device's functionality through denial-of-service attacks. Users are encouraged to upgrade to supported versions when possible to mitigate these risks.

Affected Version(s)

mH-DEVELOPER 0 < 3.0.30

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Chudzik (CERT.PL)
.