Impact
The mH-DEVELOPER smart home module embeds an identical hard‑coded SSH host key on every device, with no per‑device key generation. An attacker who extracts these keys from firmware can set up a rogue SSH server that clients will trust without warning, allowing manipulation of SSH traffic, interception of credentials, and potentially granting unauthorized remote access to the home network.
Affected Systems
Vendor F&F Filipowski’s mH-DEVELOPER product is affected. All releases prior to version 3.0.30 use the shared key; the issue is resolved in 3.0.30 and later.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity vulnerability, while no EPSS score is available and the vulnerability is not listed in CISA KEV. An attacker can exploit this flaw by first extracting the hard‑coded key (e.g., from a device, or by reverse engineering the firmware) and then deploying a fake SSH server that will be trusted by legitimate clients. This enables man‑in‑the‑middle attacks and credential interception, potentially allowing further lateral movement within the home network.
OpenCVE Enrichment