CVE-2026-29988

Summary

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

Affected Software

VendorProductVersion RangeStatus
MilesightAM102/102L V20 <= 1.4affected
MilesightAM103/103L V20 <= 1.8affected
MilesightAM304L0 <= 1.2affected
MilesightAM305L0 <= 1.2affected
MilesightAM307 V20 <= 1.4affected
MilesightAM3080 <= 1.7affected
MilesightAM308L0 <= 1.7affected
MilesightAM3190 <= 1.6affected
MilesightWS1010 <= 1.5affected
MilesightWS1360 <= 1.6affected
MilesightWS1560 <= 1.6affected
MilesightWS2010 <= 1.2affected
MilesightWS2020 <= 1.8affected
MilesightWS2030 <= 1.3affected
MilesightWS3010 <= 1.15affected
MilesightWS3030 <= 1.5affected
MilesightWS50X (2W-W11-EU) [501/502/503]0 <= 1.3affected
MilesightWS50X (3W-W11-EU) [501/502/503]0 <= 1.2affected
MilesightWS50X (3W-W12-EU) [501/502/503]0 <= 1.2affected
MilesightWS51X [513/515]0 <= 1.9affected
MilesightWS52X [523/525]0 <= 1.12affected
MilesightWS5580 <= 1.1affected
MilesightVS3210 <= 321.1.0.1-r5affected
MilesightVS3600 <= 1.2-r1affected
MilesightVS350 V30 <= 1.1affected
MilesightVS3510 <= 1.5affected
MilesightVS3300 <= 1.3affected
MilesightVS3400 <= 1.1affected
MilesightVS3410 <= 1.1affected
MilesightVS3700 <= 1.1affected
MilesightGS3010 <= 1.2affected
MilesightEM300-TH V30 <= 1.10affected
MilesightEM320-TH0 <= 1.6affected
MilesightTS201 V20 <= 1.1affected
MilesightTS30x V20 <= 1.1affected
MilesightWT201 V20 <= 1.5affected
MilesightWT211 V20 <= 1.5affected
MilesightUC5010 <= 1.6affected
MilesightUC5020 <= 1.6affected
MilesightUC511 V40 <= 1.6affected
MilesightUC512 V40 <= 1.6affected
MilesightUC521 LoRaWAN®0 <= 1.2affected
MilesightUC521 Cellular0 <= 1.3affected
MilesightEM300-DI0 <= 1.3affected
MilesightEM300-MCS V30 <= 1.10affected
MilesightEM300-MLD V30 <= 1.10affected
MilesightEM300-SLD V30 <= 1.10affected
MilesightEM300-ZLD V30 <= 1.10affected
MilesightEM320-TILT0 <= 1.3affected
MilesightEM400-TLD LoRaWAN®0 <= 1.2affected
MilesightEM400-TLD NB-IoT0 <= 1.5affected
MilesightEM400-MUD LoRaWAN®0 <= 1.2affected
MilesightEM400-MUD NB-IoT0 <= 1.6affected
MilesightEM400-UDL LoRaWAN®0 <= 1.2affected
MilesightEM410-RDL Cellular0 <= 1.1affected
MilesightEM411-RDL0 <= 1.2affected
MilesightEM500-CO2 V20 <= 1.11affected
MilesightEM500-SWL0 <= 1.11affected
MilesightEM500-LGT0 <= 1.11affected
MilesightEM500-PT100 V20 <= 1.11affected
MilesightEM500-PP0 <= 1.11affected
MilesightEM500-SMTC0 <= 1.11affected
MilesightEM500-UDL0 <= 1.11affected
MilesightAT1010 <= 1.2affected

Weaknesses

  • CWE-319: CWE-319: Cleartext Transmission of Sensitive Information

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References