CVE-2025-2909: Fermax Duoxme IOS Application

Medium severity, CVSS 6.9. EPSS: 0.1% chance of exploitation in the next 30 days.

The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.

Affected products

  • Fermax Duoxme IOS Application: before 3.3.1 (fixed in 3.3.1)

Published 2025-03-28. Last modified 2026-06-17.