CVE-2026-66890
Received Received - Intake

Hard-Coded Credentials in Milesight AIOT Camera Firmware

Vulnerability report for CVE-2026-66890, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: ICS-CERT

Description

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-798 The product contains hard-coded credentials, such as a password or cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the use of hard-coded credentials in affected products. These credentials can allow remote attackers to gain access to files with root privileges if the FTP service is reachable. This means unauthorized users could potentially read, modify, or delete sensitive files on the system.

Impact Analysis

The impact includes unauthorized remote access to sensitive files, potential data breaches, system compromise, and loss of control over the affected device. Attackers could exploit this to steal data, install malware, or disrupt operations.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, and other regulations due to unauthorized data access or breaches. Organizations may face legal penalties, fines, and reputational damage for failing to protect sensitive data.

Mitigation Strategies

Disable FTP access if not required. Change all hard-coded credentials to unique, strong passwords. Restrict network access to FTP services to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66890. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart