Description
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices.
This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated API access to building automation device controls
Action: Apply Patch
AI Analysis

Impact

The mH-DEVELOPER smart home module contains a missing authentication flaw in its authorization middleware, allowing any entity on the local network to access all HTTP API and WebSocket endpoints without a valid credential. This permits an attacker to read system information and issue raw control commands that can manipulate building automation devices, potentially disrupting normal operation or enabling malicious control of the equipment.

Affected Systems

The vulnerability affects F&F Filipowski’s mH-DEVELOPER product. All releases prior to version 3.0.30 are impacted because the missing authentication check was fixed in that release.

Risk and Exploitability

With a CVSS score of 6.4 the issue represents a medium severity vulnerability. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. An attacker must be on the same local network to exploit it, but once present can freely interact with the device, so the risk to facilities is significant if the product remains on an unsegmented network.

Generated by OpenCVE AI on September 28, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the mH-DEVELOPER module to version 3.0.30 or later to install the vendor’s authentication fix.
  • Prior to applying the patch, restrict the module’s API and WebSocket ports using network firewall rules or VLAN segmentation to prevent unauthenticated LAN access.
  • Continuously monitor the device’s logs for anomalous API calls and ensure that network segmentation keeps building automation systems isolated from general local‑network traffic.

Generated by OpenCVE AI on September 28, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in version 3.0.30
Title Missing Authentication in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-306
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 6.4, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:H/SA:H'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.622Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82930

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:12.890Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:23.550

Modified: 2026-09-28T14:17:19.200

Link: CVE-2026-82930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function