CVE-2026-82928
CVE-2026-82928 is a high-severity vulnerability with a CVSS 4.0 base score of 7.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1242.
Key facts
- Severity: High (CVSS 4.0 base score 7.7)
- EPSS exploit prediction: 0% (7th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-1242
- Published:
- Last modified:
Description
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
Frequently asked questions
- What is CVE-2026-82928?
- mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes. This issue was fixed in version 3.0.30
- How severe is CVE-2026-82928?
- CVE-2026-82928 has a CVSS 4.0 base score of 7.7, rated high severity.
- Is CVE-2026-82928 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (7th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-82928?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-82928 published?
- CVE-2026-82928 was published on 2026-09-28.
References
- https://cert.pl/posts/2026/09/CVE-2026-82928/
- https://www.fif.com.pl/pl/strona-glowna/1367-mh-developer.html
Other CWE-1242 vulnerabilities
- CVE-2025-12176 — Critical (CVSS 9.8): Undocumented administrative accounts were getting created to facilitate access for applications running on board.This…
- CVE-2025-55050 — Critical (CVSS 9.8): CWE-1242: Inclusion of Undocumented Features
- CVE-2017-20204 — Critical (CVSS 9.3): DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet…
- CVE-2023-3634 — High (CVSS 8.8): In products of the MSE6 product-family by Festo a remote authenticated, low privileged attacker could use functions of…
- CVE-2025-41756 — High (CVSS 8.1): A low-privileged remote attacker can exploit the ubr-editfile method in wwwubr.cgi, an undocumented and unused API…
- CVE-2026-24714 — High (CVSS 7.5): Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate…