PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86443 Fermax Electronica S.A.U. CVE debrief

The CVE-2026-86443 vulnerability involves cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4. This allows an attacker with local access to the device to retrieve stored credentials and impersonate the user account. The CVSS score is 6.9, indicating a medium severity. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. The official advisory or CVE record should be reviewed to validate affected scope, severity, and vendor guidance. For exposed systems, compensating controls should be reviewed while remediation is scheduled and verified. Relevant monitoring, }

Vendor
Fermax Electronica S.A.U.
Product
DuoxMe
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-18
Advisory published
2026-09-16
Advisory updated
2026-09-18

Who should care

Defenders responsible for managing Android devices and applications, particularly those using the DuoxMe application, should assess exposure and prioritize verification of the application version and implementation of compensating controls.

Why it matters

CVE-2026-86443 allows local attackers to retrieve credentials from the DuoxMe application, enabling impersonation. Defenders should verify application versions, restrict access, and monitor for exploitation attempts.

  • Defenders need to verify the DuoxMe application version on Android devices to prevent local credential retrieval.
  • Implementing measures to restrict local access to sensitive information can mitigate exploitation.
  • Monitoring for potential exploitation attempts is necessary to detect possible attacks.

Technical summary

The DuoxMe application for Android stores sensitive information in cleartext, allowing an attacker with local access to retrieve credentials and impersonate the user account. This vulnerability affects versions prior to 4.3.4 and has a CVSS score of 6.9, indicating medium severity.

Defensive priority

Defenders should prioritize verifying the version of the DuoxMe application installed on Android devices and ensuring that it is updated to version 4.3.4 or later. Additionally, defenders should consider implementing measures to restrict local access to sensitive information and monitor for potential exploitation attempts.

Recommended defensive actions

  • Verify the version of the DuoxMe application installed on Android devices and update to version 4.3.4 or later.
  • Implement measures to restrict local access to sensitive information.
  • Monitor for potential exploitation attempts.

Evidence notes

The CVE record and NVD entry provide information on the vulnerability, but details on exploitation or affected versions beyond 'prior to 4.3.4' are limited. The vendor and product names are not confirmed, with Fermax listed as a potential source.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86443 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86443

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86443 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86443

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://fermax.com/security-advisories

    539080bd-5750-4cce-b30b-eed9a4ef6dcc

  • Source reference

    Unverified legacy reference

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-2909

    539080bd-5750-4cce-b30b-eed9a4ef6dcc

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.