在 DuoMe 应用与 VEO 和 VEO-XS Wi-Fi 监测设备之间的配对过程中,若应用版本低于 4.3.4 且监测设备固件版本低于 01.50.001,家庭 Wi-Fi 凭证(即 Wi-Fi 密码)在传输时未进行加密。这使得处于同一 Wi-Fi Direct 网络上的攻击者能够截获该密码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fermax Electronica S.A.U. | DuoxMe | 0 ~ 4.3.4 | - |
|
| Fermax Electronica S.A.U. | DUOX PLUS monitor firmware (VEO Wi-Fi range) | 0 ~ 01.50.001 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86474 | 7.7 HIGH | Improper Certificate Validation in the Firmware Download vulnerability |
| CVE-2026-86585 | 7.7 HIGH | Improper Verification of the Firmware Signature vulnerability |
| CVE-2026-86443 | 6.9 MEDIUM | Cleartext Storage of Sensitive Information Vulnerability |
No comments yet