Junglewise Threat Intelligence

CVE-2026-86585: Fermax VEO and VEO-XS firmware signature verification bypass

CVE-2026-86585 · Severity: info · CVSS 7.7 · Published 2026-09-16

Executive brief

VEO and VEO-XS are Wi-Fi-enabled door entry monitors used in residential and commercial access control systems. The lack of signature verification on firmware updates allows an attacker who intercepts or controls the update delivery mechanism to install malicious firmware, potentially compromising the device's integrity and enabling unauthorized access or surveillance.

Technical details

This vulnerability is a firmware signature verification bypass in Fermax VEO and VEO-XS Wi-Fi monitors. The root cause is the absence of cryptographic signature validation on firmware update packages before installation. An attacker who can intercept or redirect firmware update traffic (e.g., via man-in-the-middle, DNS spoofing, or network compromise) can supply malicious firmware that will be accepted and executed without verification. The attack requires network-level control over the device's update channel but does not require authentication or user interaction beyond the device's automatic update process. A successful exploit allows installation of unauthorized firmware, potentially enabling full device compromise, credential theft, or use as a pivot point for further network attacks.

Affected products

  • Fermax VEO prior to 01.48.001
  • Fermax VEO-XS prior to 01.48.001

Timeline

  • 2026-09-16: disclosed

References

Related threats