CVE-2026-82932EPSS p6.2%
CVE-2026-82932CVE-2026-82932
Description
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
Scoring
| EPSS | 0.17% probability of exploitation · percentile 6.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-28 |