CVE-2026-86443 PUBLISHED

Cleartext Storage of Sensitive Information Vulnerability

Assigner: FERMAX
Reserved: 07.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
CVSS Score: 6.9

Product Status

Vendor Fermax Electronica S.A.U.
Product DuoxMe
Versions Default: unaffected
  • affected from 0 to 4.3.4 (excl.)

Credits

  • Pedro J. Núñez-Cacho Fuentes (Tunelko) finder
  • INCIBE-CERT coordinator

References

Problem Types

  • CWE-312 Cleartext Storage of Sensitive Information CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data