A vulnerability in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to install unauthorized firmware due to a lack of signature verification of firmware update packages. This issue could lead to security breaches, emphasizing the need for defenders to assess exposure and prioritize verifying the integrity of firmware updates. The CVE record and NVD vulnerability detail pag [truncated]
HIGHFermax Electronica S.A.U.CVE published 2026-09-16
VEO and VEO-XS Wi-Fi monitors, prior to version 01.48.001, have a high-severity vulnerability due to a lack of TLS certificate validation during firmware updates. This allows for man-in-the-middle attacks on the update channel. Defenders should assess exposure and prioritize updates to version 01.48.001 or later. The CVE record and NVD entry provide details, but specific version information and remediatio [truncated]
MEDIUMFermax Electronica S.A.U.CVE published 2026-09-16
The CVE-2026-86443 vulnerability involves cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4. This allows an attacker with local access to the device to retrieve stored credentials and impersonate the user account. The CVSS score is 6.9, indicating a medium severity. Affected product deployments should be identified in managed environments, and own [truncated]
HIGHFermax Electronica S.A.U.CVE published 2026-09-16
CVE-2026-85628: The DuoxMe application and VEO and VEO-XS Wi-Fi monitors have a vulnerability where they transmit home Wi-Fi credentials without encryption during the pairing process. This allows an attacker on the Wi-Fi Direct network to intercept the network password. The issue affects versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware. Defenders should assess exposure and [truncated]