7.6 CVE-2026-29988

Enriched by CISA
 

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.
https://nvd.nist.gov/vuln/detail/CVE-2026-29988

Categories

CWE-319 : Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.) Before transmitting, encrypt the data using reliable, confidentiality-protecting cryptographic protocols. When using web applications with SSL, use SSL for the entire session from login to logout, not just for the initial login page. When designing hardware platforms, ensure that approved encryption algorithms (such as those recommended by NIST) protect paths from security critical data to trusted user applications. Use tools and techniques that require manual (human) analysis, such as penetration testing, threat modeling, and interactive tools that allow the tester to record and modify an active session. These may be more effective than strictly automated techniques. This is especially the case with weaknesses that are related to design and business rules. Configure servers to use encrypted channels for communication, which may include SSL or other secure protocols. Programmable Logic Controller (PLC) sends sensitive information in plaintext, including passwords and session tokens. Building Controller uses a protocol that transmits authentication credentials in plaintext. Programmable Logic Controller (PLC) sends password in plaintext. Passwords transmitted in cleartext. Chain: Use of HTTPS cookie without "secure" flag causes it to be transmitted across unencrypted HTTP. Product sends password hash in cleartext in violation of intended policy. Remote management feature sends sensitive information including passwords in cleartext. Backup routine sends password in cleartext in email. Product transmits Blowfish encryption key in cleartext. Printer sends configuration information, including administrative password, in cleartext. Chain: cleartext transmission of the MD5 hash of password enables attacks against a server that is susceptible to replay (CWE-294). Product sends passwords in cleartext to a log server. Product sends file with cleartext passwords in e-mail message intended for diagnostic purposes.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Milesight AM102/102L V2
  • ≤ 1.4 [affected]
Milesight AM103/103L V2
  • ≤ 1.8 [affected]
Milesight AM304L
  • ≤ 1.2 [affected]
Milesight AM305L
  • ≤ 1.2 [affected]
Milesight AM307 V2
  • ≤ 1.4 [affected]
Milesight AM308
  • ≤ 1.7 [affected]
Milesight AM308L
  • ≤ 1.7 [affected]
Milesight AM319
  • ≤ 1.6 [affected]
Milesight WS101
  • ≤ 1.5 [affected]
Milesight WS136
  • ≤ 1.6 [affected]
Milesight WS156
  • ≤ 1.6 [affected]
Milesight WS201
  • ≤ 1.2 [affected]
Milesight WS202
  • ≤ 1.8 [affected]
Milesight WS203
  • ≤ 1.3 [affected]
Milesight WS301
  • ≤ 1.15 [affected]
Milesight WS303
  • ≤ 1.5 [affected]
Milesight WS50X (2W-W11-EU) [501/502/503]
  • ≤ 1.3 [affected]
Milesight WS50X (3W-W11-EU) [501/502/503]
  • ≤ 1.2 [affected]
Milesight WS50X (3W-W12-EU) [501/502/503]
  • ≤ 1.2 [affected]
Milesight WS51X [513/515]
  • ≤ 1.9 [affected]
Milesight WS52X [523/525]
  • ≤ 1.12 [affected]
Milesight WS558
  • ≤ 1.1 [affected]
Milesight VS321
  • ≤ 321.1.0.1-r5 [affected]
Milesight VS360
  • ≤ 1.2-r1 [affected]
Milesight VS350 V3
  • ≤ 1.1 [affected]
Milesight VS351
  • ≤ 1.5 [affected]
Milesight VS330
  • ≤ 1.3 [affected]
Milesight VS340
  • ≤ 1.1 [affected]
Milesight VS341
  • ≤ 1.1 [affected]
Milesight VS370
  • ≤ 1.1 [affected]
Milesight GS301
  • ≤ 1.2 [affected]
Milesight EM300-TH V3
  • ≤ 1.10 [affected]
Milesight EM320-TH
  • ≤ 1.6 [affected]
Milesight TS201 V2
  • ≤ 1.1 [affected]
Milesight TS30x V2
  • ≤ 1.1 [affected]
Milesight WT201 V2
  • ≤ 1.5 [affected]
Milesight WT211 V2
  • ≤ 1.5 [affected]
Milesight UC501
  • ≤ 1.6 [affected]
Milesight UC502
  • ≤ 1.6 [affected]
Milesight UC511 V4
  • ≤ 1.6 [affected]
Milesight UC512 V4
  • ≤ 1.6 [affected]
Milesight UC521 LoRaWAN®
  • ≤ 1.2 [affected]
Milesight UC521 Cellular
  • ≤ 1.3 [affected]
Milesight EM300-DI
  • ≤ 1.3 [affected]
Milesight EM300-MCS V3
  • ≤ 1.10 [affected]
Milesight EM300-MLD V3
  • ≤ 1.10 [affected]
Milesight EM300-SLD V3
  • ≤ 1.10 [affected]
Milesight EM300-ZLD V3
  • ≤ 1.10 [affected]
Milesight EM320-TILT
  • ≤ 1.3 [affected]
Milesight EM400-TLD LoRaWAN®
  • ≤ 1.2 [affected]
Milesight EM400-TLD NB-IoT
  • ≤ 1.5 [affected]
Milesight EM400-MUD LoRaWAN®
  • ≤ 1.2 [affected]
Milesight EM400-MUD NB-IoT
  • ≤ 1.6 [affected]
Milesight EM400-UDL LoRaWAN®
  • ≤ 1.2 [affected]
Milesight EM410-RDL Cellular
  • ≤ 1.1 [affected]
Milesight EM411-RDL
  • ≤ 1.2 [affected]
Milesight EM500-CO2 V2
  • ≤ 1.11 [affected]
Milesight EM500-SWL
  • ≤ 1.11 [affected]
Milesight EM500-LGT
  • ≤ 1.11 [affected]
Milesight EM500-PT100 V2
  • ≤ 1.11 [affected]
Milesight EM500-PP
  • ≤ 1.11 [affected]
Milesight EM500-SMTC
  • ≤ 1.11 [affected]
Milesight EM500-UDL
  • ≤ 1.11 [affected]
Milesight AT101
  • ≤ 1.2 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
No known exploits

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
102 Session Sidejacking
High
117 Interception
Medium
383 Harvesting Information via API Event Monitoring
Low
477 Signature Spoofing by Mixing Signed and Unsigned Content
High
65 Sniff Application Code
High


MITRE


Techniques

id description
T1040 Network Sniffing
T1056.004 Input Capture: Credential API Hooking
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Mitigations

id description
M1018 In cloud environments, ensure that users are not granted permissions to create or modify traffic mirrors unless this is explicitly required.
© 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.