CVE-2026-82928: CWE-1242 Inclusion of Undocumented Features or Chicken Bits in F&F Filipowski mH-DEVELOPER
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
AI Analysis
Technical Summary
CVE-2026-82928 describes a vulnerability in the mH-DEVELOPER smart home module where a hardcoded SSH public key is present in /root/.ssh/authorized_keys. The SSH daemon permits root login using this key, which starts automatically. Because the key cannot be removed without remounting the filesystem and survives factory resets, an attacker possessing the matching private key can obtain a root shell, leading to complete system compromise. The vendor states this backdoor was intended solely for service purposes. The vulnerability is fixed in version 3.0.30.
Potential Impact
An attacker with the private key corresponding to the hardcoded public key can gain root-level access to any affected device, resulting in full system compromise. The backdoor persists through factory resets, making it difficult to remove without specialized intervention.
Mitigation Recommendations
Upgrade all affected devices to version 3.0.30 or later, where this vulnerability has been fixed. Until then, devices remain vulnerable due to the persistent hardcoded key.
CVE-2026-82928: CWE-1242 Inclusion of Undocumented Features or Chicken Bits in F&F Filipowski mH-DEVELOPER
Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
CVSS v4.0
Score 7.7high
Affected software
F&F Filipowski
mH-DEVELOPER
pkg:github/f&ffilipowski/mH-DEVELOPERRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-82928 describes a vulnerability in the mH-DEVELOPER smart home module where a hardcoded SSH public key is present in /root/.ssh/authorized_keys. The SSH daemon permits root login using this key, which starts automatically. Because the key cannot be removed without remounting the filesystem and survives factory resets, an attacker possessing the matching private key can obtain a root shell, leading to complete system compromise. The vendor states this backdoor was intended solely for service purposes. The vulnerability is fixed in version 3.0.30.
Potential Impact
An attacker with the private key corresponding to the hardcoded public key can gain root-level access to any affected device, resulting in full system compromise. The backdoor persists through factory resets, making it difficult to remove without specialized intervention.
Mitigation Recommendations
Upgrade all affected devices to version 3.0.30 or later, where this vulnerability has been fixed. Until then, devices remain vulnerable due to the persistent hardcoded key.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-08-31T12:23:36.734Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aba5e98f7a7c54106a8a6f5
Added to database: 09/28/2026, 12:33:28 UTC
Last enriched: 09/28/2026, 12:47:49 UTC
Last updated: 09/29/2026, 01:57:22 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.