VYPR
Vendor

Fermax

Products
7
CVEs
5
Across products
6
Status
Private

Products

7

Recent CVEs

5
  • CVE-2026-86585HigSep 16, 2026
    risk 0.50cvss —epss 0.00

    The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

  • CVE-2026-86474HigSep 16, 2026
    risk 0.50cvss —epss 0.00

    The lack of TLS certificate validation when downloading firmware updates in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker to perform man-in-the-middle attacks on the update channel.

  • CVE-2026-85628HigSep 16, 2026
    risk 0.46cvss —epss 0.00

    Transmission of the home Wi-Fi credentials without encryption during the pairing process between the DuoxMe application and VEO and VEO-XS Wi-Fi monitors, in versions prior to 4.3.4 of the application and 01.50.001 of the monitor firmware, allows an attacker on the Wi-Fi Direct…

  • CVE-2025-2909MedMar 28, 2025
    risk 0.45cvss —epss 0.00

    The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

  • CVE-2017-16778MedDec 24, 2019
    risk 0.30cvss 4.6epss 0.01

    An access control weakness in the DTMF tone receiver of Fermax Outdoor Panel allows physical attackers to inject a Dual-Tone-Multi-Frequency (DTMF) tone to invoke an access grant that would allow physical access to a restricted floor/level. By design, only a residential unit…