CVE-2026-82930: Missing Authentication in mH-DEVELOPER
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices. This issue was fixed in version 3.0.30
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mH-DEVELOPERto a version that resolves this vulnerability.Fixed in 3.0.30
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker with access to the same LAN as the mH-DEVELOPER module can exploit it. The issue exposes both HTTP API and WebSocket endpoints without requiring valid tokens.
What could an attacker do through the exposed endpoints?
An attacker can query endpoints, obtain system information, and send raw control commands. This can allow manipulation of connected building automation devices.
Are systems running version 3.0.30 affected?
No. The issue was fixed in mH-DEVELOPER version 3.0.30.