CVE-2026-29988
8.3
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N
Summary
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Milesight | AM102/102L V2 | 0 <= 1.4 | affected |
| Milesight | AM103/103L V2 | 0 <= 1.8 | affected |
| Milesight | AM304L | 0 <= 1.2 | affected |
| Milesight | AM305L | 0 <= 1.2 | affected |
| Milesight | AM307 V2 | 0 <= 1.4 | affected |
| Milesight | AM308 | 0 <= 1.7 | affected |
| Milesight | AM308L | 0 <= 1.7 | affected |
| Milesight | AM319 | 0 <= 1.6 | affected |
| Milesight | WS101 | 0 <= 1.5 | affected |
| Milesight | WS136 | 0 <= 1.6 | affected |
| Milesight | WS156 | 0 <= 1.6 | affected |
| Milesight | WS201 | 0 <= 1.2 | affected |
| Milesight | WS202 | 0 <= 1.8 | affected |
| Milesight | WS203 | 0 <= 1.3 | affected |
| Milesight | WS301 | 0 <= 1.15 | affected |
| Milesight | WS303 | 0 <= 1.5 | affected |
| Milesight | WS50X (2W-W11-EU) [501/502/503] | 0 <= 1.3 | affected |
| Milesight | WS50X (3W-W11-EU) [501/502/503] | 0 <= 1.2 | affected |
| Milesight | WS50X (3W-W12-EU) [501/502/503] | 0 <= 1.2 | affected |
| Milesight | WS51X [513/515] | 0 <= 1.9 | affected |
| Milesight | WS52X [523/525] | 0 <= 1.12 | affected |
| Milesight | WS558 | 0 <= 1.1 | affected |
| Milesight | VS321 | 0 <= 321.1.0.1-r5 | affected |
| Milesight | VS360 | 0 <= 1.2-r1 | affected |
| Milesight | VS350 V3 | 0 <= 1.1 | affected |
| Milesight | VS351 | 0 <= 1.5 | affected |
| Milesight | VS330 | 0 <= 1.3 | affected |
| Milesight | VS340 | 0 <= 1.1 | affected |
| Milesight | VS341 | 0 <= 1.1 | affected |
| Milesight | VS370 | 0 <= 1.1 | affected |
| Milesight | GS301 | 0 <= 1.2 | affected |
| Milesight | EM300-TH V3 | 0 <= 1.10 | affected |
| Milesight | EM320-TH | 0 <= 1.6 | affected |
| Milesight | TS201 V2 | 0 <= 1.1 | affected |
| Milesight | TS30x V2 | 0 <= 1.1 | affected |
| Milesight | WT201 V2 | 0 <= 1.5 | affected |
| Milesight | WT211 V2 | 0 <= 1.5 | affected |
| Milesight | UC501 | 0 <= 1.6 | affected |
| Milesight | UC502 | 0 <= 1.6 | affected |
| Milesight | UC511 V4 | 0 <= 1.6 | affected |
| Milesight | UC512 V4 | 0 <= 1.6 | affected |
| Milesight | UC521 LoRaWAN® | 0 <= 1.2 | affected |
| Milesight | UC521 Cellular | 0 <= 1.3 | affected |
| Milesight | EM300-DI | 0 <= 1.3 | affected |
| Milesight | EM300-MCS V3 | 0 <= 1.10 | affected |
| Milesight | EM300-MLD V3 | 0 <= 1.10 | affected |
| Milesight | EM300-SLD V3 | 0 <= 1.10 | affected |
| Milesight | EM300-ZLD V3 | 0 <= 1.10 | affected |
| Milesight | EM320-TILT | 0 <= 1.3 | affected |
| Milesight | EM400-TLD LoRaWAN® | 0 <= 1.2 | affected |
| Milesight | EM400-TLD NB-IoT | 0 <= 1.5 | affected |
| Milesight | EM400-MUD LoRaWAN® | 0 <= 1.2 | affected |
| Milesight | EM400-MUD NB-IoT | 0 <= 1.6 | affected |
| Milesight | EM400-UDL LoRaWAN® | 0 <= 1.2 | affected |
| Milesight | EM410-RDL Cellular | 0 <= 1.1 | affected |
| Milesight | EM411-RDL | 0 <= 1.2 | affected |
| Milesight | EM500-CO2 V2 | 0 <= 1.11 | affected |
| Milesight | EM500-SWL | 0 <= 1.11 | affected |
| Milesight | EM500-LGT | 0 <= 1.11 | affected |
| Milesight | EM500-PT100 V2 | 0 <= 1.11 | affected |
| Milesight | EM500-PP | 0 <= 1.11 | affected |
| Milesight | EM500-SMTC | 0 <= 1.11 | affected |
| Milesight | EM500-UDL | 0 <= 1.11 | affected |
| Milesight | AT101 | 0 <= 1.2 | affected |
Weaknesses
- CWE-319: CWE-319: Cleartext Transmission of Sensitive Information
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.