Impact
The firmware update mechanism in VEO and VEO‑XS Wi‑Fi monitors does not validate TLS certificates. This omission allows an attacker who can position themselves between the monitor and the update server to intercept or modify firmware traffic. By supplying a tampered firmware package, the attacker can install malicious code on the device, thereby gaining full control over the monitor and any systems it communicates with. The weakness is a classic certificate validation flaw.
Affected Systems
Fermax Electronica S.A.U. devices using DUOX PLUS monitor firmware, specifically the VEO Wi‑Fi range, in any version older than 01.48.001.
Risk and Exploitability
The CVSS score of 7.7 indicates a serious threat, and the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based man‑in‑the‑middle during the firmware download process, requiring the attacker be able to intercept TLS traffic destined for the update server.
OpenCVE Enrichment