CVE-2026-85628
Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.
| CWE | CWE-319 |
| Vendor | fermax electronica s.a.u. |
| Product | duoxme |
| Published | Sep 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for fermax electronica s.a.u. duoxme
Be the first to know when new unknown vulnerabilities affecting fermax electronica s.a.u. duoxme are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Fermax Electronica S.A.U. / DuoxMe
0 < 4.3.4
Fermax Electronica S.A.U. / DUOX PLUS monitor firmware (VEO Wi-Fi range)
0 < 01.50.001
Credits
Pedro J. NΓΊΓ±ez-Cacho Fuentes (Tunelko) INCIBE-CERT