PT-2026-99862 · Unknown · Mh-Developer Smart Home Module

·

CVE-2026-82928

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

7.7

High

VectorAV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mH-DEVELOPER smart home module versions prior to 3.0.30
Description The software contains a hardcoded SSH public key located in the /root/.ssh/authorized keys file, which functions as a backdoor. The SSH daemon is configured to start automatically and permits root login via key authentication. An attacker possessing the corresponding private key can obtain a root shell, leading to full system compromise. This key persists after a factory reset and cannot be deleted without remounting the file system. The vendor stated this feature was intended solely for service purposes.
Recommendations Update to version 3.0.30.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82928

Affected Products

Mh-Developer Smart Home Module