DuoxMe Android 应用在 4.3.4 版本之前,存在敏感信息明文存储的漏洞。该漏洞允许拥有设备本地访问权限的攻击者提取应用存储的凭证,并据此冒充用户账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fermax Electronica S.A.U. | DuoxMe | 0 ~ 4.3.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86474 | 7.7 HIGH | Improper Certificate Validation in the Firmware Download vulnerability |
| CVE-2026-86585 | 7.7 HIGH | Improper Verification of the Firmware Signature vulnerability |
| CVE-2026-85628 | 7.0 HIGH | Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability |
No comments yet