Description
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.


This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: Credential compromise and session hijack via cleartext network traffic
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows an attacker who can observe the local network to capture all traffic sent by mH‑DEVELOPER, including passwords, authentication tokens, and device commands. The attacker can then impersonate legitimate users and command devices without authorization, potentially compromising the integrity and availability of the smart home system.

Affected Systems

Vendor F&F Filipowski’s mH‑DEVELOPER application is affected in all releases prior to version 3.0.30. The fix is implemented in that version. The product exposes a web interface and API over unencrypted HTTP, leading to credential leakage.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity. No EPSS score is available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers with local network access can intercept traffic, making the vulnerability relatively easy to exploit in an unprotected home or office environment.

Generated by OpenCVE AI on September 28, 2026 at 13:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade mH‑DEVELOPER to version 3.0.30 or later.
  • Configure the device or network to use HTTPS or a VPN, ensuring all web and API traffic is encrypted.
  • Restrict local network access by implementing VLANs or firewall rules that limit connections to the device.

Generated by OpenCVE AI on September 28, 2026 at 13:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions. This issue was fixed in version 3.0.30
Title Cleartext Transmission of Sensitive Information in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-1428
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.368Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82933

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:09.739Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:23.850

Modified: 2026-09-28T14:17:19.470

Link: CVE-2026-82933

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-1428

    Reliance on HTTP instead of HTTPS