Impact
The vulnerability is a failure to verify firmware signatures in VEO and VEO‑XS Wi‑Fi monitors prior to version 01.48.001. An attacker who can control the delivery of an update can replace the firmware with an unauthorized version, giving the attacker the ability to execute arbitrary code on the device, tamper with its functionality, and potentially use the device as a foothold in the surrounding network.
Affected Systems
Vendors: Fermax Electronica S.A.U.; product: DUOX PLUS monitor firmware (VEO Wi‑Fi range). The flaw exists in firmware releases before 01.48.001. Only devices running those older firmware revisions are affected.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, but the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s known exploited vulnerability catalog, so no widespread attacks have been recorded. An attacker would need the ability to supply a firmware image to the monitor, which can occur over an untrusted update channel. If that condition is met, the lack of signature checking allows the attacker to install malicious firmware and gain full device control.
OpenCVE Enrichment