CVE-2026-82932: Missing Firewall Configuration in mH-DEVELOPER
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mH-DEVELOPERto a version that resolves this vulnerability.Fixed in 3.0.30
Event History
Frequently Asked Questions
Who can reach the exposed services?
Any client on the same LAN can reach all listening services, including SSH, HTTP, WebSocket, and Node-RED. No access control is applied because firewall rules are not loaded at startup.
Which versions are known to be affected or fixed?
The issue is fixed in version 3.0.30. The provided information does not identify the earliest affected version.
How can I determine whether a device is exposed?
Check whether the device is running a version earlier than 3.0.30 and whether firewall rules are loaded after startup. From another client on the same LAN, exposed listening services such as SSH, HTTP, WebSocket, and Node-RED may be reachable.