VulnSea

F&F Filipowski has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 7. The median CVSS is 6.3 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
—
Last 90 days
7 prev 0

Products

  • mH-DEVELOPER 7
7
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

F&F Filipowski vulnerabilities

CVEs affecting F&F Filipowski, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-82932Medium· 5.3
today

mH-DEVELOPER smart home module does not load any firewall rules at startup

mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82935Medium· 6.9
today

mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware

mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An a…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82929Medium· 6.3
today

mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation

mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82928High· 7.7
today

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the mat…

▾ TwilightF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82936Medium· 5.9
today

mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption

mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on th…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82933Medium· 6.0
today

mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP

mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic,…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
CVE-2026-82930Medium· 6.4
today

mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication

mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, acce…

▾ SunlitF&F Filipowski · mH-DEVELOPERvia NVD
F&F Filipowski vulnerabilities (CVEs) · VulnSea