CVE-2026-85628: Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability
Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DuoxMe applicationto a version that resolves this vulnerability.Fixed in 4.3.4 - Upgrade
Upgrade
VEO and VEO-XS Wi-Fi monitors firmwareto a version that resolves this vulnerability.Fixed in 01.50.001
Event History
Frequently Asked Questions
Who can intercept the Wi-Fi password?
An attacker must be on the Wi-Fi Direct network used during pairing between the DuoxMe application and a VEO or VEO-XS Wi-Fi monitor. The issue affects the pairing process because the home Wi-Fi credentials are transmitted without encryption.
Which versions need to be updated?
Update the DuoxMe application to version 4.3.4 or later and the VEO or VEO-XS monitor firmware to version 01.50.001 or later. Versions prior to those releases are affected.
What can be done if updates cannot be applied immediately?
The provided information identifies exposure during pairing on the Wi-Fi Direct network. Avoid performing pairing while untrusted parties could access that network until the application and monitor firmware can be updated.