Impact
The mH-DEVELOPER smart home module contains a missing authentication flaw in its authorization middleware, allowing any entity on the local network to access all HTTP API and WebSocket endpoints without a valid credential. This permits an attacker to read system information and issue raw control commands that can manipulate building automation devices, potentially disrupting normal operation or enabling malicious control of the equipment.
Affected Systems
The vulnerability affects F&F Filipowski’s mH-DEVELOPER product. All releases prior to version 3.0.30 are impacted because the missing authentication check was fixed in that release.
Risk and Exploitability
With a CVSS score of 6.4 the issue represents a medium severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. An attacker must be on the same local network to exploit it, but once present can freely interact with the device, so the risk to facilities is significant if the product remains on an unsegmented network.
OpenCVE Enrichment