{"id":"CVE-2026-82932","published":"2026-09-28T13:17:23.703","lastModified":"2026-09-28T16:31:16.073","description":"mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.\n\n\nThis issue was fixed in version 3.0.30","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-923"],"vendors":[],"products":[],"references":[{"url":"https://cert.pl/posts/2026/09/CVE-2026-82928/","tags":[]},{"url":"https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}