CVE-2026-86585

Summary

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

Affected Software

VendorProductVersion RangeStatus
Fermax Electronica S.A.U.DUOX PLUS monitor firmware (VEO Wi-Fi range)0 < 01.48.001affected

Weaknesses

  • CWE-347: CWE-347 Improper Verification of Cryptographic Signature

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References