CVE-2026-29988
Summary
| CVE | CVE-2026-29988 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-26 05:18:07 UTC |
| Updated | 2026-09-09 16:04:24 UTC |
| Description | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected. |
Risk And Classification
Primary CVSS: v4.0 8.3 HIGH from [email protected]
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.001500000 probability, percentile 0.045140000 (date 2026-09-09)
Problem Types: CWE-319 | CWE-319 CWE-319: Cleartext Transmission of Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.3 | HIGH | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.3 | HIGH | CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N |
| 3.1 | [email protected] | Secondary | 7.6 | HIGH | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.6 | HIGH | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v4.0 Breakdown
Attack Vector
PhysicalAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
HighSub Availability
NoneCVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
Attack Vector
PhysicalAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Milesight | AM102/102L V2 | affected 1.4 custom | Not specified |
| CNA | Milesight | AM103/103L V2 | affected 1.8 custom | Not specified |
| CNA | Milesight | AM304L | affected 1.2 custom | Not specified |
| CNA | Milesight | AM305L | affected 1.2 custom | Not specified |
| CNA | Milesight | AM307 V2 | affected 1.4 custom | Not specified |
| CNA | Milesight | AM308 | affected 1.7 custom | Not specified |
| CNA | Milesight | AM308L | affected 1.7 custom | Not specified |
| CNA | Milesight | AM319 | affected 1.6 custom | Not specified |
| CNA | Milesight | WS101 | affected 1.5 custom | Not specified |
| CNA | Milesight | WS136 | affected 1.6 custom | Not specified |
| CNA | Milesight | WS156 | affected 1.6 custom | Not specified |
| CNA | Milesight | WS201 | affected 1.2 custom | Not specified |
| CNA | Milesight | WS202 | affected 1.8 custom | Not specified |
| CNA | Milesight | WS203 | affected 1.3 custom | Not specified |
| CNA | Milesight | WS301 | affected 1.15 custom | Not specified |
| CNA | Milesight | WS303 | affected 1.5 custom | Not specified |
| CNA | Milesight | WS50X 2W-W11-EU 501/502/503 | affected 1.3 custom | Not specified |
| CNA | Milesight | WS50X 3W-W11-EU 501/502/503 | affected 1.2 custom | Not specified |
| CNA | Milesight | WS50X 3W-W12-EU 501/502/503 | affected 1.2 custom | Not specified |
| CNA | Milesight | WS51X 513/515 | affected 1.9 custom | Not specified |
| CNA | Milesight | WS52X 523/525 | affected 1.12 custom | Not specified |
| CNA | Milesight | WS558 | affected 1.1 custom | Not specified |
| CNA | Milesight | VS321 | affected 321.1.0.1-r5 custom | Not specified |
| CNA | Milesight | VS360 | affected 1.2-r1 custom | Not specified |
| CNA | Milesight | VS350 V3 | affected 1.1 custom | Not specified |
| CNA | Milesight | VS351 | affected 1.5 custom | Not specified |
| CNA | Milesight | VS330 | affected 1.3 custom | Not specified |
| CNA | Milesight | VS340 | affected 1.1 custom | Not specified |
| CNA | Milesight | VS341 | affected 1.1 custom | Not specified |
| CNA | Milesight | VS370 | affected 1.1 custom | Not specified |
| CNA | Milesight | GS301 | affected 1.2 custom | Not specified |
| CNA | Milesight | EM300-TH V3 | affected 1.10 custom | Not specified |
| CNA | Milesight | EM320-TH | affected 1.6 custom | Not specified |
| CNA | Milesight | TS201 V2 | affected 1.1 custom | Not specified |
| CNA | Milesight | TS30x V2 | affected 1.1 custom | Not specified |
| CNA | Milesight | WT201 V2 | affected 1.5 custom | Not specified |
| CNA | Milesight | WT211 V2 | affected 1.5 custom | Not specified |
| CNA | Milesight | UC501 | affected 1.6 custom | Not specified |
| CNA | Milesight | UC502 | affected 1.6 custom | Not specified |
| CNA | Milesight | UC511 V4 | affected 1.6 custom | Not specified |
| CNA | Milesight | UC512 V4 | affected 1.6 custom | Not specified |
| CNA | Milesight | UC521 LoRaWAN | affected 1.2 custom | Not specified |
| CNA | Milesight | UC521 Cellular | affected 1.3 custom | Not specified |
| CNA | Milesight | EM300-DI | affected 1.3 custom | Not specified |
| CNA | Milesight | EM300-MCS V3 | affected 1.10 custom | Not specified |
| CNA | Milesight | EM300-MLD V3 | affected 1.10 custom | Not specified |
| CNA | Milesight | EM300-SLD V3 | affected 1.10 custom | Not specified |
| CNA | Milesight | EM300-ZLD V3 | affected 1.10 custom | Not specified |
| CNA | Milesight | EM320-TILT | affected 1.3 custom | Not specified |
| CNA | Milesight | EM400-TLD LoRaWAN | affected 1.2 custom | Not specified |
| CNA | Milesight | EM400-TLD NB-IoT | affected 1.5 custom | Not specified |
| CNA | Milesight | EM400-MUD LoRaWAN | affected 1.2 custom | Not specified |
| CNA | Milesight | EM400-MUD NB-IoT | affected 1.6 custom | Not specified |
| CNA | Milesight | EM400-UDL LoRaWAN | affected 1.2 custom | Not specified |
| CNA | Milesight | EM410-RDL Cellular | affected 1.1 custom | Not specified |
| CNA | Milesight | EM411-RDL | affected 1.2 custom | Not specified |
| CNA | Milesight | EM500-CO2 V2 | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-SWL | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-LGT | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-PT100 V2 | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-PP | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-SMTC | affected 1.11 custom | Not specified |
| CNA | Milesight | EM500-UDL | affected 1.11 custom | Not specified |
| CNA | Milesight | AT101 | affected 1.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.milesight.com/legal/vulnerabilities-in-some-milesight-sensors | [email protected] | www.milesight.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.