{"id":"CVE-2026-82933","title":"mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP","summary":"mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic,…","severity":"medium","cvss":6,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-1428"],"vendor":"F&F Filipowski","product":"mH-DEVELOPER","affected":["mH-DEVELOPER < 3.0.30"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T13:17:23.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82933","references":[{"url":"https://cert.pl/posts/2026/09/CVE-2026-82928/","label":"cvd@cert.pl"},{"url":"https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html","label":"cvd@cert.pl"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-28T13:03:49.589779Z"},"cvssSource":"cna","ingestedAt":"2026-09-28T13:09:42.238Z","slug":"CVE-2026-82933","body":"## Overview\n\nmH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.\n\n\nThis issue was fixed in version 3.0.30\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}