CVE-2026-82933: Cleartext Transmission of Sensitive Information in mH-DEVELOPER
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
mH-DEVELOPERto a version that resolves this vulnerability.Fixed in 3.0.30
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker who can observe traffic on the same network as the mH-DEVELOPER module can intercept unencrypted web interface and API communications.
What information or access could be exposed?
Passwords, authentication tokens, and device commands are sent in cleartext. Captured credentials or tokens could allow an attacker to hijack sessions.
Which version resolves the issue?
The issue was fixed in mH-DEVELOPER version 3.0.30.