CVE-2026-29988
Deferred Deferred - Pending Action

Cleartext Transmission of Sensitive Data in Milesight IoT Devices

Vulnerability report for CVE-2026-29988, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-09-09

Assigner: MITRE

Description

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-09-09
Generated
2026-09-15
AI Q&A
2026-08-26
EPSS Evaluated
2026-09-14
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
milesight iot_device *
milesight sensor *
milesight people_counter *
milesight occupancy_sensor *
milesight temperature_sensor *
milesight humidity_sensor *
milesight leakage_detection_sensor *
milesight industrial_router *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves cleartext transmission of sensitive information in the NFC interface of Milesight IoT devices. An unauthenticated attacker with physical proximity can retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via NFC read operations. These exposed keys enable decryption of LoRaWAN traffic, forging uplink and downlink frames, submitting falsified sensor data, issuing device commands, and causing legitimate frames to be rejected.

Detection Guidance

This vulnerability requires physical proximity to exploit via NFC. To detect it, check if NFC interfaces are enabled on affected Milesight devices and monitor for unauthorized NFC read attempts. No specific commands are provided in the context, but inspect device logs for NFC-related activities and ensure NFC is disabled if not needed.

Impact Analysis

An attacker could decrypt your device communications, manipulate sensor data, send unauthorized commands to devices, or disrupt legitimate operations. This could lead to data breaches, incorrect sensor readings, or operational failures in systems relying on these devices.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations if data breaches occur due to this issue.

Mitigation Strategies

Disable NFC interfaces on affected devices if not required. Update to the latest firmware versions provided by Milesight. Restrict physical access to devices to prevent unauthorized NFC interactions. Monitor LoRaWAN traffic for anomalies indicating potential exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-29988. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart