Executive brief
VEO and VEO-XS Wi-Fi monitors are used to enable home and building automation in residential and commercial settings. The monitors fail to validate TLS certificates when downloading firmware updates, allowing an attacker to intercept and modify update traffic. An attacker positioned on the network path could inject malicious firmware, leading to device compromise and potential unauthorized access to the monitored building or home.
Technical details
This vulnerability is a TLS certificate validation bypass in the firmware download mechanism of VEO and VEO-XS Wi-Fi monitors (firmware versions prior to 01.48.001). The vulnerable component fails to properly validate the TLS certificate presented by the update server, enabling man-in-the-middle (MITM) attacks. An attacker on the network path (e.g., on the same Wi-Fi network or through compromised network infrastructure) can intercept the firmware download request and serve malicious firmware without detection. The device will accept and install the unsigned malicious firmware, though a separate vulnerability (CVE-2026-86585) involving lack of firmware signature verification must also be present for full exploitation. The vulnerability is fixed in firmware version 01.48.001 and later.
Affected products
- Fermax VEO < 01.48.001
- Fermax VEO-XS < 01.48.001
Timeline
- 2026-09-16: disclosed