天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-82936 mH-DEVELOPER 智能家居模块资源耗尽拒绝服务漏洞

影响局域网攻击者可耗尽内存导致服务崩溃

MEDIUM
暂无 CVSS 评分
AI 研判

mH-DEVELOPER 智能家居模块的 Express 服务将 bodyParser 的 JSON 与 URL 编码请求体上限设为 250 MB,且未对请求体大小做有效约束。攻击者可在局域网内发送超大请求体,耗尽 RAM 缓冲区,触发内存溢出并导致 fh-node 进程崩溃,形成拒绝服务。

影响范围

mH-DEVELOPER smart home module

mH-DEVELOPER smart home module 3.0.30 之前的版本;具体受影响版本范围暂无更详细的公开信息。

漏洞详情

漏洞类型为不受控资源消耗导致的拒绝服务。成因是 Express bodyParser 允许高达 250 MB 的请求体,服务端解析时会将其载入内存。攻击者只需发送大体积请求即可占用大量内存,使 fh-node 进程因内存不足而崩溃。

利用条件与风险

攻击者需位于同一局域网,且攻击成功与否受设备当前内存占用影响,并非完全可控;但由于 CVE-2026-82930 导致所有接口可未授权访问,局域网内任意用户均可发起该攻击,实战风险较高。

修复建议

官方已在 3.0.30 版本中修复,建议升级至该版本或更高版本;临时缓解可限制请求体大小、增加内存监控或限制局域网访问。

原始情报

mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.

This issue was fixed in version 3.0.30