CVE-2026-82932: F&f Filipowski Mh-Developer

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30

Affected products

Published 2026-09-28. Last modified 2026-09-28.