πŸ” CVE Alert

CVE-2026-85628

UNKNOWN 0.0

Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.

CWE CWE-319
Vendor fermax electronica s.a.u.
Product duoxme
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for fermax electronica s.a.u. duoxme

Be the first to know when new unknown vulnerabilities affecting fermax electronica s.a.u. duoxme are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Fermax Electronica S.A.U. / DuoxMe
0 < 4.3.4
Fermax Electronica S.A.U. / DUOX PLUS monitor firmware (VEO Wi-Fi range)
0 < 01.50.001

References

NVD β†— CVE.org β†— EPSS Data β†—
fermax.com: https://fermax.com/security-advisories

Credits

Pedro J. NΓΊΓ±ez-Cacho Fuentes (Tunelko) INCIBE-CERT