CVE-2026-82928High· 7.7▾ TwilightmH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the mat…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.
This issue was fixed in version 3.0.30
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-82932Medium· 5.3mH-DEVELOPER smart home module does not load any firewall rules at startup
CVE-2026-82929Medium· 6.3mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation
CVE-2026-82935Medium· 6.9mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware
CVE-2026-82933Medium· 6.0mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP
CVE-2026-82936Medium· 5.9mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption
CVE-2026-82930Medium· 6.4mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication