PT-2026-99867 · Debian+2 · Debian 8+2
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
mH-DEVELOPER versions prior to 3.0.30
Description
The smart home module uses an end-of-life and unsupported Debian 8 operating system and Node.js runtime v17.0.1 in its production firmware. This reliance on obsolete components exposes the device to known security flaws that no longer receive patches, potentially allowing an attacker to execute arbitrary code, access sensitive data, or trigger a denial of service.
Recommendations
Update to version 3.0.30.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian 8
Node.Js
Mh-Developer