Description
Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Published: 2026-09-16
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Theft and Impersonation
Action: Update
AI Analysis

Impact

The DuoxMe Android application stores user credentials in cleartext in versions prior to 4.3.4, allowing an attacker with local device access to recover those credentials and impersonate the account holder. This vulnerability is classified as CWE-312, cleartext storage of sensitive information.

Affected Systems

Affected products are Fermax Electronica S.A.U.'s DuoxMe app for Android. All releases older than version 4.3.4 contain the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is 0.00099 (< 1%) and the issue is not listed in the CISA KEV catalog, indicating a very low exploitation probability and no widespread known exploitation. The attack vector requires local device access, meaning the attacker must physically or otherwise gain direct access to the device to read the stored credentials. Under those conditions, the vulnerability can lead to credential theft and impersonation, posing a moderate risk to affected users.

Generated by OpenCVE AI on September 16, 2026 at 14:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade DuoxMe to version 4.3.4 or later where credential storage is secured.
  • If updating is not immediately possible, delete or clear any stored credentials from the device or move them to encrypted storage.
  • Ensure the device uses full encryption and restrict physical access to prevent attackers from gaining local device access.

Generated by OpenCVE AI on September 16, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
Description Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.
Title Cleartext Storage of Sensitive Information Vulnerability
Weaknesses CWE-312
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: FERMAX

Published:

Updated: 2026-09-16T13:53:24.680Z

Reserved: 2026-09-07T12:41:14.377Z

Link: CVE-2026-86443

cve-icon Vulnrichment

Updated: 2026-09-16T13:53:21.550Z

cve-icon NVD

Status : Received

Published: 2026-09-16T10:16:54.707

Modified: 2026-09-16T14:17:11.707

Link: CVE-2026-86443

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T15:00:07Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information