天下漏洞,尽知其名
CRITICAL

CVE-2026-82928 mH-DEVELOPER 智能家居模块硬编码SSH公钥后门漏洞

影响攻击者可利用硬编码私钥获取设备 root 权限,完全控制系统

CRITICAL
暂无 CVSS 评分
AI 研判

mH-DEVELOPER 智能家居模块的 /root/.ssh/authorized_keys 中内置了硬编码 SSH 公钥,构成潜在后门。SSH 服务默认允许 root 通过密钥登录并自动启动,持有对应私钥的攻击者可登录任意受影响设备并获得 root shell。厂商称该功能仅用于服务目的。

影响范围

mH-DEVELOPER smart home module

mH-DEVELOPER smart home module,3.0.30 之前的版本受影响,该问题已在 3.0.30 中修复。

漏洞详情

漏洞类型为硬编码凭据/后门。设备固件中预置了固定的 SSH 公钥,且 SSH 守护进程允许 root 使用密钥认证登录并开机自启。攻击者只需获得与该公钥配对的私钥,即可远程登录设备获取 root 权限。该密钥无法在不重新挂载文件系统的情况下删除,且恢复出厂设置后依然存在。

利用条件与风险

利用前提是攻击者掌握匹配的私钥并能通过网络访问目标设备的 SSH 端口。一旦满足条件,可完全控制设备,风险极高;若私钥泄露或被逆向提取,影响范围将扩大至所有未修复设备。

修复建议

官方已在 3.0.30 版本中修复,建议尽快升级至该版本或更高版本。临时缓解措施包括限制 SSH 端口的外部访问、通过防火墙或网络隔离阻断未授权连接;由于密钥在恢复出厂设置后仍存在,仅靠重置无法清除。

原始情报

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.

This issue was fixed in version 3.0.30