Default SSL Certificates Vulnerability in Milesight AIOT Cameras
CVE-2026-32644
9.2CRITICAL
What is CVE-2026-32644?
Specific firmware versions of Milesight AIOT cameras utilize SSL certificates that are issued with default private keys. This weakness can allow unauthorized actors to exploit the cameras, potentially leading to access, data interception, and manipulation of video feeds. It is crucial for users to update their firmware to eliminate this security risk and ensure proper encryption practices are in place.
Affected Version(s)
MS-C2964-RFLPC 0
MS-C2966-RFLWPC 0
MS-C2966-X12RLPC 0
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Souvik Kandar reported these vulnerabilities to CISA
