Description
The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.
Published: 2026-09-16
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Device Compromise through Unauthorized Firmware
Action: Apply Signed Update
AI Analysis

Impact

The vulnerability is a failure to verify firmware signatures in VEO and VEO‑XS Wi‑Fi monitors prior to version 01.48.001. An attacker who can control the delivery of an update can replace the firmware with an unauthorized version, giving the attacker the ability to execute arbitrary code on the device, tamper with its functionality, and potentially use the device as a foothold in the surrounding network.

Affected Systems

Vendors: Fermax Electronica S.A.U.; product: DUOX PLUS monitor firmware (VEO Wi‑Fi range). The flaw exists in firmware releases before 01.48.001. Only devices running those older firmware revisions are affected.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity, but the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s known exploited vulnerability catalog, so no widespread attacks have been recorded. An attacker would need the ability to supply a firmware image to the monitor, which can occur over an untrusted update channel. If that condition is met, the lack of signature checking allows the attacker to install malicious firmware and gain full device control.

Generated by OpenCVE AI on September 18, 2026 at 09:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install the latest firmware version 01.48.001 or newer that includes signature verification.
  • Before applying any update, verify the firmware’s digital signature using the vendor’s published key.
  • Restrict firmware updates to a trusted source; block or monitor any unsolicited firmware traffic.
  • If immediate firmware upgrade is not possible, isolate the device from other network assets or disable its update capability until a patch is available.

Generated by OpenCVE AI on September 18, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Fermax
Fermax duox Plus Monitor Firmware (veo Wi-fi Range)
Vendors & Products Fermax
Fermax duox Plus Monitor Firmware (veo Wi-fi Range)

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.
Title Improper Verification of the Firmware Signature vulnerability
Weaknesses CWE-347
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Fermax Duox Plus Monitor Firmware (veo Wi-fi Range)
cve-icon MITRE

Status: PUBLISHED

Assigner: FERMAX

Published:

Updated: 2026-09-16T17:47:00.863Z

Reserved: 2026-09-08T07:00:51.689Z

Link: CVE-2026-86585

cve-icon Vulnrichment

Updated: 2026-09-16T17:46:54.498Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T11:16:44.070

Modified: 2026-09-18T19:44:10.957

Link: CVE-2026-86585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:45:06Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature