CVE-2026-85628
Received Received - Intake

Transmission of Wi-Fi Credentials Without Encryption in DuoxMe App and VEO Monitors

Vulnerability report for CVE-2026-85628, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: FERMAX

Description

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-09-16
AI Q&A
2026-09-16
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
duoxme application to 4.3.4 (exc)
veo monitor_firmware to 01.50.001 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the transmission of home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors. The issue affects versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware.

Detection Guidance

This vulnerability involves unencrypted transmission of Wi-Fi credentials during pairing between the DuoxMe app and VEO/VEO-XS monitors. Detection requires monitoring Wi-Fi Direct network traffic for unencrypted credential exchanges during the pairing process.

Impact Analysis

An attacker on the Wi-Fi Direct network could intercept the network password, potentially gaining unauthorized access to the Wi-Fi network and any connected devices or data.

Mitigation Strategies

Update the DuoxMe application to version 4.3.4 or later and the VEO/VEO-XS monitor firmware to version 01.50.001 or later to ensure encrypted credential transmission during pairing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85628. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart