PT-2026-99862 · Unknown · Mh-Developer Smart Home Module
CVSS v4.0
7.7
High
| Vector | AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mH-DEVELOPER smart home module versions prior to 3.0.30
Description
The software contains a hardcoded SSH public key located in the
/root/.ssh/authorized keys file, which functions as a backdoor. The SSH daemon is configured to start automatically and permits root login via key authentication. An attacker possessing the corresponding private key can obtain a root shell, leading to full system compromise. This key persists after a factory reset and cannot be deleted without remounting the file system. The vendor stated this feature was intended solely for service purposes.Recommendations
Update to version 3.0.30.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mh-Developer Smart Home Module