Out-of-Bounds Memory Access Vulnerability in Milesight AIOT Cameras
CVE-2026-20766

8.6HIGH

Key Information:

Vendor

Milesight

Vendor
CVE Published:
27 April 2026

What is CVE-2026-20766?

An out-of-bounds memory access vulnerability has been identified in certain firmware versions of Milesight AIOT cameras. This flaw may allow unauthorized access to memory, potentially leading to unpredictable behavior, crashes, or execution of arbitrary code. Users should ensure that they are using the latest firmware to mitigate risks associated with this vulnerability. For further details on affected versions and updates, please refer to Milesight's official firmware support page.

Affected Version(s)

MS-C2964-RFLPC 0

MS-C2966-RFLWPC 0

MS-C2966-X12RLPC 0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Souvik Kandar reported these vulnerabilities to CISA
.