Executive brief
The DuoxMe application, used for video intercom and home monitoring on Android devices, stores user credentials in plaintext without encryption. An attacker with physical access to an unlocked device can read these stored credentials from the app's local data and gain full control of the user's account, impersonating them for unauthorized access to connected devices and home systems.
Technical details
The vulnerability is a cleartext storage of sensitive information issue (CWE-312) in the DuoxMe Android app versions before 4.3.4, where user credentials are stored unencrypted in the device's local storage. The attack vector is local: an attacker with physical access to an unlocked or compromised Android device can trivially extract the credentials using standard file access or forensic tools. No authentication or network access is required. Once credentials are obtained, an attacker can authenticate as the victim user and gain full access to paired smart home devices and meeting functionality. A fix is available in version 4.3.4 and later.
Affected products
- Fermax DuoxMe < 4.3.4
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 4.3.4