CVE-2026-29988

Summary

CVECVE-2026-29988
StatePUBLISHED
Assignermitre
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-08-26 05:18:07 UTC
Updated2026-09-09 16:04:24 UTC
DescriptionA cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

Risk And Classification

Primary CVSS: v4.0 8.3 HIGH from [email protected]

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS: 0.001500000 probability, percentile 0.045140000 (date 2026-09-09)

Problem Types: CWE-319 | CWE-319 CWE-319: Cleartext Transmission of Sensitive Information


VersionSourceTypeScoreSeverityVector
4.0[email protected]Secondary8.3HIGHCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/C...
4.0CNACVSS8.3HIGHCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N
3.1[email protected]Secondary7.6HIGHCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
3.1CNACVSS7.6HIGHCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v4.0 Breakdown

Attack Vector
Physical
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Sub Conf.
None
Sub Integrity
High
Sub Availability
None

CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVSS v3.1 Breakdown

Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Milesight AM102/102L V2 affected 1.4 custom Not specified
CNA Milesight AM103/103L V2 affected 1.8 custom Not specified
CNA Milesight AM304L affected 1.2 custom Not specified
CNA Milesight AM305L affected 1.2 custom Not specified
CNA Milesight AM307 V2 affected 1.4 custom Not specified
CNA Milesight AM308 affected 1.7 custom Not specified
CNA Milesight AM308L affected 1.7 custom Not specified
CNA Milesight AM319 affected 1.6 custom Not specified
CNA Milesight WS101 affected 1.5 custom Not specified
CNA Milesight WS136 affected 1.6 custom Not specified
CNA Milesight WS156 affected 1.6 custom Not specified
CNA Milesight WS201 affected 1.2 custom Not specified
CNA Milesight WS202 affected 1.8 custom Not specified
CNA Milesight WS203 affected 1.3 custom Not specified
CNA Milesight WS301 affected 1.15 custom Not specified
CNA Milesight WS303 affected 1.5 custom Not specified
CNA Milesight WS50X 2W-W11-EU 501/502/503 affected 1.3 custom Not specified
CNA Milesight WS50X 3W-W11-EU 501/502/503 affected 1.2 custom Not specified
CNA Milesight WS50X 3W-W12-EU 501/502/503 affected 1.2 custom Not specified
CNA Milesight WS51X 513/515 affected 1.9 custom Not specified
CNA Milesight WS52X 523/525 affected 1.12 custom Not specified
CNA Milesight WS558 affected 1.1 custom Not specified
CNA Milesight VS321 affected 321.1.0.1-r5 custom Not specified
CNA Milesight VS360 affected 1.2-r1 custom Not specified
CNA Milesight VS350 V3 affected 1.1 custom Not specified
CNA Milesight VS351 affected 1.5 custom Not specified
CNA Milesight VS330 affected 1.3 custom Not specified
CNA Milesight VS340 affected 1.1 custom Not specified
CNA Milesight VS341 affected 1.1 custom Not specified
CNA Milesight VS370 affected 1.1 custom Not specified
CNA Milesight GS301 affected 1.2 custom Not specified
CNA Milesight EM300-TH V3 affected 1.10 custom Not specified
CNA Milesight EM320-TH affected 1.6 custom Not specified
CNA Milesight TS201 V2 affected 1.1 custom Not specified
CNA Milesight TS30x V2 affected 1.1 custom Not specified
CNA Milesight WT201 V2 affected 1.5 custom Not specified
CNA Milesight WT211 V2 affected 1.5 custom Not specified
CNA Milesight UC501 affected 1.6 custom Not specified
CNA Milesight UC502 affected 1.6 custom Not specified
CNA Milesight UC511 V4 affected 1.6 custom Not specified
CNA Milesight UC512 V4 affected 1.6 custom Not specified
CNA Milesight UC521 LoRaWAN affected 1.2 custom Not specified
CNA Milesight UC521 Cellular affected 1.3 custom Not specified
CNA Milesight EM300-DI affected 1.3 custom Not specified
CNA Milesight EM300-MCS V3 affected 1.10 custom Not specified
CNA Milesight EM300-MLD V3 affected 1.10 custom Not specified
CNA Milesight EM300-SLD V3 affected 1.10 custom Not specified
CNA Milesight EM300-ZLD V3 affected 1.10 custom Not specified
CNA Milesight EM320-TILT affected 1.3 custom Not specified
CNA Milesight EM400-TLD LoRaWAN affected 1.2 custom Not specified
CNA Milesight EM400-TLD NB-IoT affected 1.5 custom Not specified
CNA Milesight EM400-MUD LoRaWAN affected 1.2 custom Not specified
CNA Milesight EM400-MUD NB-IoT affected 1.6 custom Not specified
CNA Milesight EM400-UDL LoRaWAN affected 1.2 custom Not specified
CNA Milesight EM410-RDL Cellular affected 1.1 custom Not specified
CNA Milesight EM411-RDL affected 1.2 custom Not specified
CNA Milesight EM500-CO2 V2 affected 1.11 custom Not specified
CNA Milesight EM500-SWL affected 1.11 custom Not specified
CNA Milesight EM500-LGT affected 1.11 custom Not specified
CNA Milesight EM500-PT100 V2 affected 1.11 custom Not specified
CNA Milesight EM500-PP affected 1.11 custom Not specified
CNA Milesight EM500-SMTC affected 1.11 custom Not specified
CNA Milesight EM500-UDL affected 1.11 custom Not specified
CNA Milesight AT101 affected 1.2 custom Not specified

References

ReferenceSourceLinkTags
www.milesight.com/legal/vulnerabilities-in-some-milesight-sensors [email protected] www.milesight.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report