CVE-2026-82928
EUVD-2026-8822828.09.2026, 13:17
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration