PT-2026-99865 · F&F Filipowski · Mh-Developer

·

CVE-2026-82932

·

Publicado

2026-09-28

·

Atualizado

2026-09-28

CVSS v4.0

5.3

Média

VetorAV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-82932

Produtos afetados

Mh-Developer