VulnSea

Fermax Electronica S.A.U. has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 7.3 (high). Most affected products: DUOX PLUS monitor firmware (VEO Wi-Fi range) (2), com.fermax.blue.app (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.3
Publish → KEV
—
Last 90 days
4 prev 0

Products

  • DUOX PLUS monitor firmware (VEO Wi-Fi range) 2
  • com.fermax.blue.app 2
Follow Fermax Electronica S.A.U.:RSS feedSave a search →Embed badge ↗
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Fermax Electronica S.A.U. vulnerabilities

CVEs affecting Fermax Electronica S.A.U., newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-86585High· 7.7
1w ago

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

▾ TwilightFermax Electronica S.A.U. · DUOX PLUS monitor firmware (VEO Wi-Fi range)EPSS 0.16%via NVD
CVE-2026-86474High· 7.7
1w ago

The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

▾ TwilightFermax Electronica S.A.U. · DUOX PLUS monitor firmware (VEO Wi-Fi range)EPSS 0.13%via NVD
CVE-2026-86443Medium· 6.9
1w ago

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the us…

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the us…

▾ SunlitFermax Electronica S.A.U. · com.fermax.blue.appEPSS 0.10%via NVD
CVE-2026-85628High· 7.0
1w ago

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmwar…

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmwar…

▾ TwilightFermax Electronica S.A.U. · com.fermax.blue.appEPSS 0.09%via NVD
Fermax Electronica S.A.U. vulnerabilities (CVEs) · VulnSea