« Volver al listado

Mh-developer

Mh-developer Smart Home Module: vulnerabilidades y CVE

Mh-developer Smart Home Module tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-82936Media (5.9)0.17%—28 sept 2026
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An…
CVE-2026-82935Media (6.9)0.37%—28 sept 2026
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive…
CVE-2026-82933Media (6)0.21%—28 sept 2026
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can…
CVE-2026-82932Media (5.3)0.17%—28 sept 2026
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client…
CVE-2026-82930Media (6.4)0.21%—28 sept 2026
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query…
CVE-2026-82929Media (6.3)0.24%—28 sept 2026
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients…
CVE-2026-82928Alta (7.7)0.18%—28 sept 2026
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1190 Exploit Public-Facing Application2
  3. T1021.006 Windows Remote Management1
  4. T1059 Command and Scripting Interpreter1
  5. T1078 Valid Accounts1
  6. T1212 Exploitation for Credential Access1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.