Impact
During the pairing process between the DuoxMe application and VEO or VEO‑XS Wi‑Fi monitors, versions before 4.3.4 of the app and 01.50.001 of the monitor firmware transmit the home Wi‑Fi credentials in cleartext. This allows an attacker on the same Wi‑Fi Direct network to capture the network password, thereby enabling unauthorized access to the property’s Wi‑Fi network. The vulnerability is a classic example of cleartext transmission of sensitive information (CWE‑319).
Affected Systems
Vendors Fermax Electronica S.A.U. provide the affected products: the DuoxMe application and the DUOX PLUS monitor firmware (VEO Wi‑Fi range). The flaw exists in DuoxMe versions earlier than 4.3.4 and in monitor firmware earlier than 01.50.001.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, while an EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis. The flaw is not listed in the CISA KEV catalog. An attacker only needs to be on the same Wi‑Fi Direct network to sniff the unencrypted credentials; no elevated privileges are required. Therefore the risk is moderate but the likelihood of real‑world exploitation remains low.
OpenCVE Enrichment