F&F Filipowski mH-DEVELOPER
7 known vulnerabilities in F&F Filipowski mH-DEVELOPER, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82936 CVSS 5.9 medium mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is…
- CVE-2026-82935 CVSS 6.9 medium mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware…
- CVE-2026-82933 CVSS 6.0 medium mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device…
- CVE-2026-82932 CVSS 5.3 medium mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP…
- CVE-2026-82930 CVSS 6.4 medium mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints…
- CVE-2026-82929 CVSS 6.3 medium mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who…
- CVE-2026-82928 CVSS 7.7 high mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH…