CVE-2026-86585: Improper Verification of the Firmware Signature vulnerability
The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VEO Wi-Fi monitorsto a version that resolves this vulnerability.Fixed in 01.48.001 - Upgrade
Upgrade
VEO-XS Wi-Fi monitorsto a version that resolves this vulnerability.Fixed in 01.48.001
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must control delivery of a firmware update package to the affected monitor. The available information does not specify how that delivery path could be controlled.
Which devices should be remediated?
VEO and VEO-XS Wi-Fi monitors running firmware earlier than 01.48.001 are affected. Update affected devices to 01.48.001 or later.
What is the impact of successful exploitation?
An attacker able to control update delivery can install unauthorised firmware on the device.