Decoding the world of cybersecurity

·

CERT Polska finds seven building-controller flaws

CERT Polska has disclosed multiple vulnerabilities in the mH-DEVELOPER smart-building controller, including authentication failures, hard-coded keys, exposed services, and unencrypted traffic.

CERT Polska finds seven building-controller flaws
Summary
  • The flaws affect F&F Filipowski mH-DEVELOPER versions earlier than 3.0.30.
  • CERT Polska identified weaknesses involving hard-coded keys, missing API authentication, network exposure, and cleartext communications.
  • The research used an LLM during discovery, but CERT Polska says the findings were manually verified and coordinated with the vendor.

A Polish smart-building controller has been found to contain a collection of security weaknesses capable of exposing control functions, credentials, and device communications to attackers on affected networks.

CERT Polska disclosed seven vulnerabilities on 28 September following coordinated work with manufacturer F&F Filipowski. The flaws affect mH-DEVELOPER versions earlier than 3.0.30.

The findings span several different classes of weakness rather than a single implementation mistake. One vulnerability involves a hard-coded SSH public key in the device’s authorised-keys configuration. CERT Polska said possession of the corresponding private key could provide root access and that the key survives a factory reset. The vendor said the functionality was intended for servicing.

Another issue concerns the use of the same SSH host keys across devices, weakening the trust that should distinguish one system from another. Researchers also found that authorisation tokens were not properly verified in middleware protecting HTTP API and WebSocket endpoints, potentially allowing an unauthenticated user on the local network to issue commands to connected building-automation equipment.

Separate findings cover the absence of firewall rules at startup and the use of unencrypted HTTP for web-interface and API traffic. CERT Polska said the latter could expose passwords, tokens, and device commands to interception by someone able to observe the same network.

The disclosure is significant because building-control technology occupies an awkward boundary between conventional IT and operational systems. A controller can expose familiar services such as HTTP and SSH while ultimately influencing physical functions elsewhere in the environment. Weak access controls at the network layer can therefore have consequences beyond the device itself.

That distinction will become increasingly relevant as the EU’s Cyber Resilience Act moves connected-product security further into regulatory requirements covering design, vulnerability handling, and lifecycle support. Products used in buildings, industrial environments, and other connected settings can remain deployed for far longer than typical consumer software, making update processes and component maintenance part of the long-term risk picture.

CERT Polska also disclosed an unusual detail about the research process: the investigation used the GLM 5.2 large language model. The organisation said the resulting findings were manually verified and discussed with the vendor before coordinated disclosure.

That separation is important. An AI system assisting vulnerability research does not independently establish that a security flaw exists. Manual validation, reproducibility, vendor coordination, and technical review remain necessary before a finding can be treated as reliable.

The affected versions also contained unmaintained third-party components and a resource-management weakness, broadening the case beyond access control. Taken together, the flaws show how security debt can accumulate across authentication, cryptography, communications, component lifecycle, and service exposure inside one embedded platform.

F&F Filipowski has addressed the disclosed issues in version 3.0.30. For operators, the disclosure provides a concrete example of why connected-building equipment increasingly needs to be managed as maintained infrastructure rather than treated as a fixed appliance installed once and left unchanged.

×