Description
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.


This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unrestricted LAN Access to Services
Action: Immediate Update
AI Analysis

Impact

The vulnerability arises from the absence of any firewall configuration in the mH‑DEVELOPER smart home module. When the device starts up, it does not load firewall rules, leaving all listening services—including SSH, HTTP, WebSocket, and Node‑RED—fully exposed on the local network with no access control. This allows any client on the same LAN to reach every service directly, potentially enabling unauthorized configuration changes or execution of malicious code. The weakness is classified as a lack of firewall rule configuration (CWE‑923). No additional privileges or authentication are required to exploit the exposed endpoints.

Affected Systems

Affected systems include devices running the mH‑DEVELOPER product from F&F Filipowski. The vulnerability applies to all releases before version 3.0.30, which incorporated the firewall fix. No other versions are referenced in the advisory.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact; the EPSS score is not available, and the vulnerability is not in the KEV catalog. The attack vector is local network (LAN) access, with no authentication required. An attacker only needs connectivity to the device’s IP on the local subnet to contact the exposed services. Because the flaw allows direct interaction with administrative interfaces, it poses a significant threat to confidentiality and integrity of the managed devices, though its impact is limited to the local network segment.

Generated by OpenCVE AI on September 28, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch by upgrading the device to version 3.0.30 or later so that firewall rules are loaded at startup.
  • If an upgrade is not possible, isolate the mH‑DEVELOPER device behind a network firewall or VLAN that blocks inbound connections from the untrusted LAN, ensuring that only authorized hosts can reach the exposed services.
  • Disable or restrict unnecessary services on the device—such as SSH, HTTP, WebSocket, and Node‑RED—through the device configuration or by closing the corresponding ports on the external router.

Generated by OpenCVE AI on September 28, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30
Title Missing Firewall Configuration in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-923
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.496Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82932

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:11.465Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:23.703

Modified: 2026-09-28T14:17:19.330

Link: CVE-2026-82932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:00:17Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints