Impact
The mH-DEVELOPER smart home module includes a hardcoded SSH public key in the root authorized_keys file, enabling an attacker who possesses the matching private key to log in as root through SSH. Because the SSH daemon starts automatically and permits root login via key authentication, the attacker can obtain a root shell and thus gain complete control of the device. This backdoor survives factory resets and cannot be removed without remounting the file system.
Affected Systems
The vulnerability affects all versions of F&F Filipowski’s mH-DEVELOPER firmware released before version 3.0.30. Current releases starting with 3.0.30 contain the fix that removes the backdoor key and disables the hardcoded root authentication.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity that allows full system compromise. While the EPSS score is not provided, the exploit is straightforward: an attacker must possess the pre‑known private key, which once obtained grants full control over any device running the affected firmware. The vulnerability is not listed in CISA’s KEV catalog, but its remote nature and the ease of exploitation make it a critical risk if an authorized key is compromised or discovered. Attackers could target devices over the local network or the Internet if SSH is exposed, thereby executing the attack.
OpenCVE Enrichment