CVE-2026-82929: Use of Shared Cryptographic Key in mH-DEVELOPER
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception. This issue was fixed in version 3.0.30
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mH-DEVELOPERto a version that resolves this vulnerability.Fixed in 3.0.30
Event History
Frequently Asked Questions
Which deployments are affected?
mH-DEVELOPER installations running a version earlier than 3.0.30 are affected because they use shared hard-coded SSH host keys rather than generating unique keys per device.
What does an attacker need to exploit this issue?
The attacker must obtain the shared SSH host keys from the firmware and be able to position a rogue SSH server where a client attempts to connect. The client may then trust the attacker-controlled server without a host-key warning.
What is the practical impact of a successful attack?
A successful man-in-the-middle attack can allow interception of credentials supplied by clients connecting over SSH.
How can I remediate the issue?
Upgrade mH-DEVELOPER to version 3.0.30, which fixes the shared hard-coded SSH host keys issue.