Description
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Man-in-the-middle attacks enabling credential theft via shared SSH host keys
Action: Immediate Patch
AI Analysis

Impact

The mH-DEVELOPER smart home module embeds an identical hard‑coded SSH host key on every device, with no per‑device key generation. An attacker who extracts these keys from firmware can set up a rogue SSH server that clients will trust without warning, allowing manipulation of SSH traffic, interception of credentials, and potentially granting unauthorized remote access to the home network.

Affected Systems

Vendor F&F Filipowski’s mH-DEVELOPER product is affected. All releases prior to version 3.0.30 use the shared key; the issue is resolved in 3.0.30 and later.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity vulnerability, while no EPSS score is available and the vulnerability is not listed in CISA KEV. An attacker can exploit this flaw by first extracting the hard‑coded key (e.g., from a device, or by reverse engineering the firmware) and then deploying a fake SSH server that will be trusted by legitimate clients. This enables man‑in‑the‑middle attacks and credential interception, potentially allowing further lateral movement within the home network.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the firmware to version 3.0.30 or later to replace the shared key with unique per‑device keys.
  • If upgrading is not immediately possible, restrict SSH access to known IP addresses or blocks, disable password authentication in favor of key‑based authentication, and ensure devices are isolated from untrusted networks.
  • Monitor network traffic for unexpected SSH connections and verify firmware integrity to detect any rogue servers that may have been set up.

Generated by OpenCVE AI on September 28, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This issue was fixed in version 3.0.30
Title Use of Shared Cryptographic Key in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-321
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.766Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82929

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:14.248Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:23.407

Modified: 2026-09-28T14:17:19.060

Link: CVE-2026-82929

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key