CVE-2026-85628: Cleartext Transmission of Sensitive Information in the Pairing Process vulnerability

Published Sep 16, 2026
·
Updated

Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct network to intercept the network password.

Affected Software

3 affected components
DuoxMe DuoxMe application<4.3.4
VEO Wi-Fi monitor<01.50.001
VEO-XS Wi-Fi monitor<01.50.001

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DuoxMe application to a version that resolves this vulnerability.

    Fixed in 4.3.4
  2. Upgrade

    Upgrade VEO and VEO-XS Wi-Fi monitors firmware to a version that resolves this vulnerability.

    Fixed in 01.50.001

Event History

Sep 16, 2026
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
DescriptionWeakness

Frequently Asked Questions

1

Who can intercept the Wi-Fi password?

An attacker must be on the Wi-Fi Direct network used during pairing between the DuoxMe application and a VEO or VEO-XS Wi-Fi monitor. The issue affects the pairing process because the home Wi-Fi credentials are transmitted without encryption.

2

Which versions need to be updated?

Update the DuoxMe application to version 4.3.4 or later and the VEO or VEO-XS monitor firmware to version 01.50.001 or later. Versions prior to those releases are affected.

3

What can be done if updates cannot be applied immediately?

The provided information identifies exposure during pairing on the Wi-Fi Direct network. Avoid performing pairing while untrusted parties could access that network until the application and monitor firmware can be updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203