Command Injection Vulnerability in Milesight Cameras
CVE-2026-32649
7.3HIGH
What is CVE-2026-32649?
A command injection vulnerability has been identified in the web server of specific firmware versions of Milesight cameras. This flaw allows an attacker to execute arbitrary commands on the affected devices, potentially compromising the security and integrity of the camera system. Users are advised to update to the latest firmware versions to mitigate the risk associated with this vulnerability.
Affected Version(s)
MS-C2964-RFLPC 0
MS-C2966-RFLWPC 0
MS-C2966-X12RLPC 0
References
CVSS V4
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Souvik Kandar reported these vulnerabilities to CISA
