Description
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.


This issue was fixed in version 3.0.30
Published: 2026-09-28
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via resource exhaustion
Action: Patch
AI Analysis

Impact

The mH‑DEVELOPER smart‑home module exposes an Express HTTP server that parses JSON and URL‑encoded bodies with a 250 MB limit. An attacker with local network access can send a request that exceeds available memory, causing an out‑of‑memory error and crashing the fh‑node process. This results in the device becoming unavailable until it is restarted. Since the BodyParser configuration is permissive, the attack does not require privilege escalation and any LAN user can trigger it because all endpoints are unauthenticated, increasing the attack surface.

Affected Systems

The vulnerability affects F&F Filipowski’s mH‑DEVELOPER product. The exact affected version is unspecified, but the issue was resolved in release 3.0.30; any earlier version is considered vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity; EPSS is not available and the flaw is not listed in the CISA KEV catalog, but the attack vector is local network. Successful exploitation depends on the device’s current memory state but does not require special privileges, making the risk tangible for facilities where the device is exposed to an untrusted LAN segment.

Generated by OpenCVE AI on September 28, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update mH‑DEVELOPER to version 3.0.30 or newer.
  • If an upgrade is not feasible, restrict or block LAN traffic to the device using a firewall or VLAN to prevent untrusted users from sending large payloads.
  • As an interim workaround, lower the body‑parser size limit in Express or implement application‑level rate limiting on POST and PUT endpoints.
  • Monitor system memory usage and request logs for signs of unusually large requests and disallow or drop them.

Generated by OpenCVE AI on September 28, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack. This issue was fixed in version 3.0.30
Title Denial of Service in mH-DEVELOPER
First Time appeared F F Filipowski
F F Filipowski mh-developer
Weaknesses CWE-770
CPEs cpe:2.3:a:f_f_filipowski:mh-developer:*:*:*:*:*:*:*:*
Vendors & Products F F Filipowski
F F Filipowski mh-developer
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

F F Filipowski Mh-developer
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-28T13:31:28.116Z

Reserved: 2026-08-31T12:23:36.734Z

Link: CVE-2026-82936

cve-icon Vulnrichment

Updated: 2026-09-28T13:24:06.608Z

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:24.150

Modified: 2026-09-28T14:17:19.740

Link: CVE-2026-82936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T13:30:18Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling