Medium severityNVD Advisory· Published Sep 28, 2026· Updated Sep 28, 2026
CVE-2026-82933
CVE-2026-82933
Description
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=3.0.30
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.