Full Report
CERT Polska has received a report about 7 vulnerabilities (from CVE-2026-82928 to CVE-2026-82930 and CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 and CVE-2026-82936) found in F&F Filipowski mH-DEVELOPER devices.
Analysis Summary
# Vulnerability: Multiple Flaws in F&F Filipowski mH-DEVELOPER Smart Home Devices
## CVE Details
- **CVE ID:** CVE-2026-82928, CVE-2026-82929, CVE-2026-82930, CVE-2026-82932, CVE-2026-82933, CVE-2026-82935, CVE-2026-82936
- **CVSS Score:** Not explicitly provided in text (Estimated High/Critical based on "Full System Compromise")
- **CWE:**
- CWE-1242 (Undocumented Features/Backdoor)
- CWE-321 (Hard-coded Cryptographic Key)
- CWE-306 (Missing Authentication)
- CWE-923 (Improper Restriction of Communication Channel)
- CWE-1428 (Use of HTTP instead of HTTPS)
- CWE-1104 (Unmaintained Third-Party Components)
- CWE-770 (Allocation of Resources Without Throttling)
## Affected Systems
- **Products:** F&F Filipowski mH-DEVELOPER (Smart Home Module)
- **Versions:** All versions prior to 3.0.30
- **Configurations:** Standard production firmware settings; particularly vulnerable when connected to a Local Area Network (LAN).
## Vulnerability Description
Multiple security flaws exist in the mH-DEVELOPER module, ranging from design weaknesses to configuration errors:
- **Backdoor Access:** A hardcoded SSH public key in the root directory allows anyone with the corresponding private key to gain full root access.
- **Authentication Failure:** The authorization middleware fails to verify tokens, leaving HTTP API and WebSocket endpoints exposed.
- **Lack of Network Security:** The device ships without firewall rules, exposing all services (SSH, Node-RED, etc.) to the LAN.
- **Insecure Transport:** Traffic is sent via unencrypted HTTP, allowing for credential sniffing.
- **Legacy Components:** The system runs on end-of-life Debian 8 and Node.js v17.0.1.
- **Denial of Service:** The system accepts massive 250MB JSON request bodies, which can be used to exhaust RAM and crash the `fh-node` process.
## Exploitation
- **Status:** PoC available (Discovered during research by CERT Polska)
- **Complexity:** Low
- **Attack Vector:** Network (primarily LAN)
## Impact
- **Confidentiality:** Total (Cleartext traffic, hardcoded keys, and unauthenticated API access)
- **Integrity:** Total (Ability to send raw control commands to building automation and gain root shell)
- **Availability:** Total (Resource exhaustion leading to system crashes)
## Remediation
### Patches
- **Update to Version 3.0.30** or later. The vendor has released this version to address the identified vulnerabilities.
### Workarounds
- Isolate the mH-DEVELOPER device on a dedicated VLAN with no access to the broader internet or untrusted local devices.
- Implement external firewall rules to restrict access to ports 22 (SSH), 80 (HTTP), and WebSocket ports at the network layer.
## Detection
- **Indicators of Compromise:** Presence of unauthorized SSH logins, unusual large HTTP POST requests (up to 250MB), or unexpected automated commands being sent to building hardware.
- **Detection methods:** Network scanning to identify exposed services on the LAN and monitoring for unencrypted sensitive data in transit.
## References
- CERT Polska Advisory: [https://cert.pl/en/posts/2026/09/vulnerabilities-in-ff-filipowski-mh-developer-devices/](https://cert.pl/en/posts/2026/09/vulnerabilities-in-ff-filipowski-mh-developer-devices/)
- CVE Records: [https://www.cve.org/CVERecord?id=CVE-2026-82928](https://www.cve.org/CVERecord?id=CVE-2026-82928)
- Vendor Website: [https://www.fif.com.pl/en/](https://www.fif.com.pl/en/)