Cleartext Transmission Vulnerability in Milesight IoT Devices
CVE-2026-29988

8.3HIGH

Key Information:

Vendor

Milesight

Vendor
CVE Published:
26 August 2026

What is CVE-2026-29988?

A vulnerability exists in the NFC interface of several Milesight IoT device models that allows an unauthenticated attacker with physical proximity to access sensitive keys. This cleartext transmission flaw can enable malicious actors to retrieve LoRaWAN NwkSKey and AppSKey values via NFC read operations. Consequently, exploited keys may lead to decryption of LoRaWAN traffic, forgery of uplink and downlink frames, submission of bogus sensor data, execution of device commands, and rejection of legitimate frames.

Affected Version(s)

AM102/102L V2 0 <= 1.4

AM103/103L V2 0 <= 1.8

AM304L 0 <= 1.2

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.