Impact
The vulnerability arises from the absence of any firewall configuration in the mH‑DEVELOPER smart home module. When the device starts up, it does not load firewall rules, leaving all listening services—including SSH, HTTP, WebSocket, and Node‑RED—fully exposed on the local network with no access control. This allows any client on the same LAN to reach every service directly, potentially enabling unauthorized configuration changes or execution of malicious code. The weakness is classified as a lack of firewall rule configuration (CWE‑923). No additional privileges or authentication are required to exploit the exposed endpoints.
Affected Systems
Affected systems include devices running the mH‑DEVELOPER product from F&F Filipowski. The vulnerability applies to all releases before version 3.0.30, which incorporated the firewall fix. No other versions are referenced in the advisory.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact; the EPSS score is not available, and the vulnerability is not in the KEV catalog. The attack vector is local network (LAN) access, with no authentication required. An attacker only needs connectivity to the device’s IP on the local subnet to contact the exposed services. Because the flaw allows direct interaction with administrative interfaces, it poses a significant threat to confidentiality and integrity of the managed devices, though its impact is limited to the local network segment.
OpenCVE Enrichment