在 VEO 和 VEO-XS Wi-Fi 监控设备中,01.48.001 之前版本的固件更新包缺乏签名验证,使得能够控制更新分发的攻击者可以安装未经授权的固件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fermax Electronica S.A.U. | DUOX PLUS monitor firmware (VEO Wi-Fi range) | 0 ~ 01.48.001 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86474 | 7.7 HIGH | Improper Certificate Validation in the Firmware Download vulnerability |
| CVE-2026-85628 | 7.0 HIGH | Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability |
| CVE-2026-86443 | 6.9 MEDIUM | Cleartext Storage of Sensitive Information Vulnerability |
No comments yet