Impact
The vulnerability allows an attacker who can observe the local network to capture all traffic sent by mH‑DEVELOPER, including passwords, authentication tokens, and device commands. The attacker can then impersonate legitimate users and command devices without authorization, potentially compromising the integrity and availability of the smart home system.
Affected Systems
Vendor F&F Filipowski’s mH‑DEVELOPER application is affected in all releases prior to version 3.0.30. The fix is implemented in that version. The product exposes a web interface and API over unencrypted HTTP, leading to credential leakage.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity. No EPSS score is available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. Attackers with local network access can intercept traffic, making the vulnerability relatively easy to exploit in an unprotected home or office environment.
OpenCVE Enrichment