Fermax Logo
Fermax Logo
  • Contacto
  • Área privada
  1. Security Advisories

Security advisories

On this page you will find all the information about the vulnerabilities we have analysed and fixed in relation to our connected products and services.

Please contact us using the button below if you find a vulnerability that is not listed in the tables below. For more information about our vulnerability management policy, please visit this page.

Report vulnerability
DUOX PLUS MEET
DuoxMe app VEO / VEO-XS monitors
MeetMe app

DuoxMe app

Name CVE CVSS 4.0 Affected version Description
Cleartext storage of sensitive information vulnerability. CVE-2026-86443 6.9 < 4.3.4 Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Cleartext transmission of sensitive information in the pairing process vulnerability. CVE-2026-85628 7.0 < 4.3.4 Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.
Lack of encryption vulnerability in DuoxMe. CVE-2025-2909 6.9 < 3.3.1 The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

VEO / VEO-XS monitors

Name CVE CVSS 4.0 Affected version Description
Improper verification of the firmware signature vulnerability. CVE-2026-86585 7.7 < 01.48.001 The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.
Improper certificate validation in the firmware download vulnerability. CVE-2026-86474 7.7 < 01.48.001 The lack of TLS certificate validation in the firmware update download of VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.
Cleartext transmission of sensitive information in the pairing process vulnerability. CVE-2026-85628 7.0 < 01.50.001 Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.

MeetMe app

Name CVE CVSS 4.0 Affected version Description
Insecure Sensitive Information Storage vulnerability. CVE-2025-10971 8.8 < v2.2.6 Insecure storage of sensitive information in the MeetMe application for iOS and Android, in versions prior to v2.2.6, allows an attacker to retrieve sensitive data embedded in the application.
Improper Restriction of Excessive Authentication Attempts vulnerability. CVE-2025-2911 5.3 < v2024-09 Unauthorised access to the call forwarding service system in MeetMe products in versions prior to 2024-09 allows an attacker to identify multiple users and perform brute force attacks via extensions.
User enumeration vulnerability. CVE-2025-2910 6.9 < v2024-09 User enumeration in the password reset module of the MeetMe authentication service in versions prior to 2024-09 allows an attacker to determine whether an email address is registered through specific error messages.
Insufficiently Protected Credentials vulnerability. CVE-2025-2908 8.5 < v2024-09 The exposure of credentials in the call forwarding configuration module in MeetMe products in versions prior to 2024-09 allows an attacker to gain access to some important assets via configuration files.
  • FERMAX WORLDWIDE
  • España
  • Internacional Español
  • International English
  • International Français
  • Portugal
  • United Kingdom
  • France
  • Belgium - Français
  • Belgium - Nederlands
  • Polska
  • Norsk
  • Svenska