Description
Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft and Impersonation
Action: Update
AI Analysis

Impact

The DuoxMe Android application stores user credentials in cleartext in versions prior to 4.3.4, allowing an attacker with local device access to recover those credentials and impersonate the account holder. This vulnerability is classified as CWE-312, cleartext storage of sensitive information.

Affected Systems

Affected products are Fermax Electronica S.A.U.'s DuoxMe app for Android. All releases older than version 4.3.4 contain the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is 0.00099 (< 1%) and the issue is not listed in the CISA KEV catalog, indicating a very low exploitation probability and no widespread known exploitation. The attack vector requires local device access, meaning the attacker must physically or otherwise gain direct access to the device to read the stored credentials. Under those conditions, the vulnerability can lead to credential theft and impersonation, posing a moderate risk to affected users.

Generated by OpenCVE AI on September 18, 2026 at 11:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DuoxMe to version 4.3.4 or later where credential storage is secured.
  • If updating is not immediately possible, delete or clear any stored credentials from the device or move them to encrypted storage.
  • Ensure the device uses full encryption and restrict physical access to prevent attackers from gaining local device access.

Generated by OpenCVE AI on September 18, 2026 at 11:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fermax
Fermax duoxme
Vendors & Products Fermax
Fermax duoxme

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Title Cleartext Storage of Sensitive Information Vulnerability
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: FERMAX

Published:

Updated: 2026-09-16T13:53:24.680Z

Reserved: 2026-09-07T12:41:14.377Z

Link: CVE-2026-86443

cve-icon Vulnrichment

Updated: 2026-09-16T13:53:21.550Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T10:16:54.707

Modified: 2026-09-18T19:44:10.957

Link: CVE-2026-86443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T11:30:06Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information