{"id":"CVE-2026-82929","published":"2026-09-28T13:17:23.407","lastModified":"2026-09-28T16:31:16.073","description":"mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.\nThis issue was fixed in version 3.0.30","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-321"],"vendors":[],"products":[],"references":[{"url":"https://cert.pl/posts/2026/09/CVE-2026-82928/","tags":[]},{"url":"https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}