OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-82928

HIGH · CVSS 7.7 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The mH-DEVELOPER smart home module contains a hardcoded SSH public key in the authorized_keys file, allowing root access via key authentication, which can be exploited by an attacker possessing the corresponding private key. This vulnerability leads to full system compromise, as the attacker can gain a root shell on any affected device, and the key persists even after a factory reset. Organizations using this module should prioritize remediation by updating to version 3.0.30 to mitigate the risk of unauthorized access.

CVE
CVE-2026-82928
Severity
HIGH
CVSS
7.7
EPSS
0.18%

Original NVD Description

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in versionĀ 3.0.30