Cleartext Transmission Vulnerability in Milesight IoT Devices
CVE-2026-29988
8.3HIGH
Key Information:
- Vendor
Milesight
- Vendor
- CVE Published:
- 26 August 2026
What is CVE-2026-29988?
A vulnerability exists in the NFC interface of several Milesight IoT device models that allows an unauthenticated attacker with physical proximity to access sensitive keys. This cleartext transmission flaw can enable malicious actors to retrieve LoRaWAN NwkSKey and AppSKey values via NFC read operations. Consequently, exploited keys may lead to decryption of LoRaWAN traffic, forgery of uplink and downlink frames, submission of bogus sensor data, execution of device commands, and rejection of legitimate frames.
Affected Version(s)
AM102/102L V2 0 <= 1.4
AM103/103L V2 0 <= 1.8
AM304L 0 <= 1.2
