Cleartext Storage of Sensitive Information Vulnerability
Summary
| CVE | CVE-2026-86443 |
|---|---|
| State | PUBLISHED |
| Assigner | FERMAX |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 10:16:54 UTC |
| Updated | 2026-09-16 14:17:11 UTC |
| Description | Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account. |
Risk And Classification
Primary CVSS: v4.0 6.9 MEDIUM from 539080bd-5750-4cce-b30b-eed9a4ef6dcc
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-312 | CWE-312 CWE-312 Cleartext Storage of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 539080bd-5750-4cce-b30b-eed9a4ef6dcc | Secondary | 6.9 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.9 | MEDIUM | CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
CVSS v4.0 Breakdown
Attack Vector
LocalAttack Complexity
LowAttack Requirements
PresentPrivileges Required
HighUser Interaction
NoneConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
HighSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fermax Electronica S.A.U. | DuoxMe | affected 4.3.4 semver | Android |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| nvd.nist.gov/vuln/detail/CVE-2025-2909 | 539080bd-5750-4cce-b30b-eed9a4ef6dcc | nvd.nist.gov | |
| fermax.com/security-advisories | 539080bd-5750-4cce-b30b-eed9a4ef6dcc | fermax.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Pedro J. Núñez-Cacho Fuentes (Tunelko) (en)
CNA: INCIBE-CERT (en)
There are currently no legacy QID mappings associated with this CVE.