PT-2026-99867 · Debian+2 · Debian 8+2

·

CVE-2026-82935

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mH-DEVELOPER versions prior to 3.0.30
Description The smart home module uses an end-of-life and unsupported Debian 8 operating system and Node.js runtime v17.0.1 in its production firmware. This reliance on obsolete components exposes the device to known security flaws that no longer receive patches, potentially allowing an attacker to execute arbitrary code, access sensitive data, or trigger a denial of service.
Recommendations Update to version 3.0.30.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82935

Affected Products

Debian 8
Node.Js
Mh-Developer