Executive brief
DuoxMe is a mobile application used to pair and configure Fermax VEO and VEO-XS Wi-Fi monitors (surveillance or monitoring devices). During the initial pairing process, the application transmits the user's home Wi-Fi network password in plaintext over the Wi-Fi Direct connection, allowing anyone on that network to intercept and obtain the password. An attacker gaining the Wi-Fi credentials can access the home network and compromise connected devices and data.
Technical details
This vulnerability is a cleartext transmission of sensitive information (CWE-319) in the pairing handshake between the DuoxMe mobile application and VEO/VEO-XS Wi-Fi monitor devices. The root cause is the lack of encryption when transmitting Wi-Fi credentials during device pairing. An attacker positioned on the Wi-Fi Direct network during the pairing process can passively intercept network traffic and extract the plaintext Wi-Fi password. No authentication or user interaction beyond initiating the pairing is required. The vulnerability affects DuoxMe application versions prior to 4.3.4 and monitor firmware prior to 01.50.001. Patches are available in DuoxMe 4.3.4 and firmware 01.50.001.
Affected products
- Fermax DuoxMe prior to 4.3.4
- Fermax VEO Wi-Fi monitor prior to 01.50.001
- Fermax VEO-XS Wi-Fi monitor prior to 01.50.001
Timeline
- 2026-09-16: disclosed