Description
The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized firmware injection leading to remote code execution
Action: Immediate Patch
AI Analysis

Impact

The firmware update mechanism in VEO and VEO‑XS Wi‑Fi monitors does not validate TLS certificates. This omission allows an attacker who can position themselves between the monitor and the update server to intercept or modify firmware traffic. By supplying a tampered firmware package, the attacker can install malicious code on the device, thereby gaining full control over the monitor and any systems it communicates with. The weakness is a classic certificate validation flaw.

Affected Systems

Fermax Electronica S.A.U. devices using DUOX PLUS monitor firmware, specifically the VEO Wi‑Fi range, in any version older than 01.48.001.

Risk and Exploitability

The CVSS score of 7.7 indicates a serious threat, and the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network‑based man‑in‑the‑middle during the firmware download process, requiring the attacker be able to intercept TLS traffic destined for the update server.

Generated by OpenCVE AI on September 18, 2026 at 10:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the device firmware to version 01.48.001 or later.
  • Configure firewalls or gateways to block connections to vendor firmware update servers except for known, trusted update URLs.
  • Disable automatic firmware updates on the device and require manual approval for any firmware installation.

Generated by OpenCVE AI on September 18, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fermax
Fermax duox Plus Monitor Firmware (veo Wi-fi Range)
Vendors & Products Fermax
Fermax duox Plus Monitor Firmware (veo Wi-fi Range)

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.
Title Improper Certificate Validation in the Firmware Download vulnerability
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Fermax Duox Plus Monitor Firmware (veo Wi-fi Range)
cve-icon MITRE

Status: PUBLISHED

Assigner: FERMAX

Published:

Updated: 2026-09-16T13:25:32.339Z

Reserved: 2026-09-07T15:03:37.487Z

Link: CVE-2026-86474

cve-icon Vulnrichment

Updated: 2026-09-16T13:25:29.103Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T10:16:54.947

Modified: 2026-09-18T19:44:10.957

Link: CVE-2026-86474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T10:30:07Z

Weaknesses
  • CWE-295

    Improper Certificate Validation