---
id: CVE-2026-86443
title: >-
  Cleartext storage of sensitive information in the DuoxMe application for
  Android, in versions prior to 4.3.4, allows an attacker with local access to
  the device to retrieve the credentials stored by the application and
  impersonate the us…
summary: >-
  Cleartext storage of sensitive information in the DuoxMe application for
  Android, in versions prior to 4.3.4, allows an attacker with local access to
  the device to retrieve the credentials stored by the application and
  impersonate the us…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N'
cwe:
  - CWE-312
vendor: Fermax Electronica S.A.U.
product: com.fermax.blue.app
affected:
  - com.fermax.blue.app < 4.3.4
published: '2026-09-16'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:44:10.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86443'
references:
  - url: 'https://fermax.com/security-advisories'
    label: 539080bd-5750-4cce-b30b-eed9a4ef6dcc
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-2909'
    label: 539080bd-5750-4cce-b30b-eed9a4ef6dcc
tags:
  - nvd
  - cve.org
epss: 0.00104
epssPercentile: 0.00933
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T13:50:50.226469Z'
cvssSource: cna
ingestedAt: '2026-09-16T09:53:11.607Z'
---

## Overview

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
