---
id: CVE-2026-82930
title: >-
  mH-DEVELOPER smart home module does not verify tokens in its authorization
  middleware, leaving all HTTP API and WebSocket endpoints accessible without
  authentication
summary: >-
  mH-DEVELOPER smart home module does not verify tokens in its authorization
  middleware, leaving all HTTP API and WebSocket endpoints accessible without
  authentication. An unauthenticated attacker on the LAN can query these
  endpoints, acce…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:H/SA:H'
cwe:
  - CWE-306
vendor: F&F Filipowski
product: mH-DEVELOPER
affected:
  - mH-DEVELOPER < 3.0.30
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T13:17:23.550'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82930'
references:
  - url: 'https://cert.pl/posts/2026/09/CVE-2026-82928/'
    label: cvd@cert.pl
  - url: 'https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html'
    label: cvd@cert.pl
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-28T13:19:38.932853Z'
cvssSource: cna
ingestedAt: '2026-09-28T13:09:42.237Z'
---

## Overview

mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices.
This issue was fixed in version 3.0.30

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
