rootpwn

critical · CVSS v3 9.8 · CVSS v4 5.3

CVE-2026-82932

mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, includin…

Description

mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service. This issue was fixed in version 3.0.30

Scores

Severity
critical
CVSS v2
7.5
CVSS v3
9.8
CVSS v4
5.3
EPSS
—

← All CVEs