Impact
The mH‑DEVELOPER smart home module contains an end‑of‑life Debian 8 distribution and a Node.js runtime v17.0.1 that is no longer updated. These components carry publicly known vulnerabilities that expose the device to arbitrary code execution, unauthorized data access, or denial of service. The weakness is classified under CWE‑1104 and arises from using unsupported components that are susceptible to known exploits.
Affected Systems
The affected product is F&F Filipowski's mH‑DEVELOPER smart home module. Firmware builds that ship with Debian 8 and Node.js v17.0.1 are vulnerable; the release notes indicate that hardening was applied in firmware version 3.0.30, so versions prior to 3.0.30 remain at risk.
Risk and Exploitability
The CVSS score of 6.9 denotes a moderate severity, and although EPSS data is not available, the lack of active patches for Debian 8 and Node.js v17.0.1 suggests a realistic threat. The vulnerability is not listed in CISA’s KEV catalog, but the device is network‑connected, so an attacker could target it remotely if they can reach the exposed interfaces. Based on the description, it is inferred that the attack vector is likely remote exploitation of the unpatched Node.js or Debian components.
OpenCVE Enrichment