CVE-2026-82932: F&f Filipowski Mh-Developer
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
Affected products
- F&f Filipowski Mh-Developer: before 3.0.30 (fixed in 3.0.30)
Published 2026-09-28. Last modified 2026-09-28.