Command Injection Vulnerability in Milesight Cameras
CVE-2026-32649

7.3HIGH

Key Information:

Vendor

Milesight

Vendor
CVE Published:
27 April 2026

What is CVE-2026-32649?

A command injection vulnerability has been identified in the web server of specific firmware versions of Milesight cameras. This flaw allows an attacker to execute arbitrary commands on the affected devices, potentially compromising the security and integrity of the camera system. Users are advised to update to the latest firmware versions to mitigate the risk associated with this vulnerability.

Affected Version(s)

MS-C2964-RFLPC 0

MS-C2966-RFLWPC 0

MS-C2966-X12RLPC 0

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Souvik Kandar reported these vulnerabilities to CISA
.