CyberRota Analysis
AI-GeneratedThe mH-DEVELOPER smart home module contains a hardcoded SSH public key in the authorized_keys file, allowing root access via key authentication, which can be exploited by an attacker possessing the corresponding private key. This vulnerability leads to full system compromise, as the attacker can gain a root shell on any affected device, and the key persists even after a factory reset. Organizations using this module should prioritize remediation by updating to version 3.0.30 to mitigate the risk of unauthorized access.
Original NVD Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in versionĀ 3.0.30