CERT Polska disclosed seven vulnerabilities in F&F Filipowski mH-DEVELOPER building-automation modules, affecting versions before 3.0.30: CVE-2026-82928, CVE-2026-82929, CVE-2026-82930, CVE-2026-82932, CVE-2026-82933, CVE-2026-82935, and CVE-2026-82936. The issues include a hardcoded SSH authorized key enabling potential root compromise, shared SSH host keys enabling man-in-the-middle attacks, and absent API and WebSocket authentication that lets an unauthenticated party on the local network control building-automation functions.
Additional weaknesses leave services exposed on the LAN because firewall rules are not loaded, send web and API traffic through unencrypted HTTP, and use end-of-life Debian 8 and Node.js 17.0.1 components. Oversized requests can also exhaust resources and crash the fh-node process; the missing API authentication makes this denial-of-service condition effectively unauthenticated. F&F Filipowski remediated the reported vulnerabilities in mH-DEVELOPER version 3.0.30, and affected organizations should upgrade promptly and restrict device network access until patched.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
F&F Filipowski fixed all seven reported vulnerabilities in mH-DEVELOPER version 3.0.30.
CERT Polska coordinated disclosure of seven vulnerabilities in F&F Filipowski mH-DEVELOPER smart-home modules affecting versions before 3.0.30. The flaws include root access through a hardcoded SSH key, shared SSH host keys, missing API authentication, LAN service exposure, cleartext HTTP, unsupported components, and a denial-of-service condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.