{"id":"CVE-2026-82928","published":"2026-09-28T13:17:23.253","lastModified":"2026-09-28T17:17:50.883","description":"mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.\n\n\nThis issue was fixed in version 3.0.30","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-1242"],"vendors":[],"products":[],"references":[{"url":"https://cert.pl/posts/2026/09/CVE-2026-82928/","tags":[]},{"url":"https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}