Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.


This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: Full system compromise via unauthorized root access
Action: Apply Patch
AI Analysis

Impact

The mH-DEVELOPER smart home module includes a hardcoded SSH public key in the root authorized_keys file, enabling an attacker who possesses the matching private key to log in as root through SSH. Because the SSH daemon starts automatically and permits root login via key authentication, the attacker can obtain a root shell and thus gain complete control of the device. This backdoor survives factory resets and cannot be removed without remounting the file system.

Affected Systems

The vulnerability affects all versions of F&F Filipowski’s mH-DEVELOPER firmware released before version 3.0.30. Current releases starting with 3.0.30 contain the fix that removes the backdoor key and disables the hardcoded root authentication.

Risk and Exploitability

The CVSS score of 7.7 indicates a high severity that allows full system compromise. While the EPSS score is not provided, the exploit is straightforward: an attacker must possess the pre‑known private key, which once obtained grants full control over any device running the affected firmware. The vulnerability is not listed in CISA’s KEV catalog, but its remote nature and the ease of exploitation make it a critical risk if an authorized key is compromised or discovered. Attackers could target devices over the local network or the Internet if SSH is exposed, thereby executing the attack.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the firmware to version 3.0.30 or later, which removes the hardcoded key and disables the insecure root SSH login.
  • Reconfigure the SSH daemon to disable key authentication for the root account or set PermitRootLogin to no, ensuring that no private key can grant root access.
  • Perform a factory reset on affected devices and re‑install a clean firmware image, then disable or remove any residual root SSH key files.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
Title Undocumented access path in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-1242
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T12:11:40.726Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82928

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:23.253

Modified: 2026-09-28T13:17:23.253

Link: CVE-2026-82928

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-1242

    Inclusion of Undocumented Features or Chicken Bits