Impact
The mH‑DEVELOPER smart‑home module exposes an Express HTTP server that parses JSON and URL‑encoded bodies with a 250 MB limit. An attacker with local network access can send a request that exceeds available memory, causing an out‑of‑memory error and crashing the fh‑node process. This results in the device becoming unavailable until it is restarted. Since the BodyParser configuration is permissive, the attack does not require privilege escalation and any LAN user can trigger it because all endpoints are unauthenticated, increasing the attack surface.
Affected Systems
The vulnerability affects F&F Filipowski’s mH‑DEVELOPER product. The exact affected version is unspecified, but the issue was resolved in release 3.0.30; any earlier version is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity; EPSS is not available and the flaw is not listed in the CISA KEV catalog, but the attack vector is local network. Successful exploitation depends on the device’s current memory state but does not require special privileges, making the risk tangible for facilities where the device is exposed to an untrusted LAN segment.
OpenCVE Enrichment