Skip to main content
EPSS 0.2%top 95%

CVE-2026-29988: CWE-319: Cleartext Transmission of Sensitive Information in Milesight AM102/102L V2

0
High
VulnerabilityCVE-2026-29988cvecve-2026-29988cwe-319
Published: 08/26/2026 (08/26/2026, 03:14:26 UTC)
Source: CVE Database V5
Vendor/Project: Milesight
Product: AM102/102L V2

Description

CVE-2026-29988 is a high-severity vulnerability affecting the NFC interface of multiple Milesight AM102/102L V2 IoT devices. It allows an unauthenticated attacker with physical proximity to retrieve sensitive LoRaWAN keys transmitted in cleartext. These keys include NwkSKey, AppSKey, and D2D keys, which can be exploited to decrypt traffic, forge frames, submit false data, and disrupt legitimate communications.

CVSS v4.0

Score 8.3high

Attack Vector
Physical
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
High
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N

Affected software

Milesight

AM102/102L V2

Affected versions
>=0 <=1.4

Milesight

AM103/103L V2

Affected versions
>=0 <=1.8

Milesight

AM304L

Affected versions
>=0 <=1.2

Milesight

AM305L

Affected versions
>=0 <=1.2

Milesight

AM307 V2

Affected versions
>=0 <=1.4

Milesight

AM308

Affected versions
>=0 <=1.7

Milesight

AM308L

Affected versions
>=0 <=1.7

Milesight

AM319

Affected versions
>=0 <=1.6

Milesight

WS101

Affected versions
>=0 <=1.5

Milesight

WS136

Affected versions
>=0 <=1.6

Milesight

WS156

Affected versions
>=0 <=1.6

Milesight

WS201

Affected versions
>=0 <=1.2

Milesight

WS202

Affected versions
>=0 <=1.8

Milesight

WS203

Affected versions
>=0 <=1.3

Milesight

WS301

Affected versions
>=0 <=1.15

Milesight

WS303

Affected versions
>=0 <=1.5

Milesight

WS50X (2W-W11-EU) [501/502/503]

Affected versions
>=0 <=1.3

Milesight

WS50X (3W-W11-EU) [501/502/503]

Affected versions
>=0 <=1.2

Milesight

WS50X (3W-W12-EU) [501/502/503]

Affected versions
>=0 <=1.2

Milesight

WS51X [513/515]

Affected versions
>=0 <=1.9

Milesight

WS52X [523/525]

Affected versions
>=0 <=1.12

Milesight

WS558

Affected versions
>=0 <=1.1

Milesight

VS321

Affected versions
>=0 <=321.1.0.1-r5

Milesight

VS360

Affected versions
>=0 <=1.2-r1

Milesight

VS350 V3

Affected versions
>=0 <=1.1

Milesight

VS351

Affected versions
>=0 <=1.5

Milesight

VS330

Affected versions
>=0 <=1.3

Milesight

VS340

Affected versions
>=0 <=1.1

Milesight

VS341

Affected versions
>=0 <=1.1

Milesight

VS370

Affected versions
>=0 <=1.1

Milesight

GS301

Affected versions
>=0 <=1.2

Milesight

EM300-TH V3

Affected versions
>=0 <=1.10

Milesight

EM320-TH

Affected versions
>=0 <=1.6

Milesight

TS201 V2

Affected versions
>=0 <=1.1

Milesight

TS30x V2

Affected versions
>=0 <=1.1

Milesight

WT201 V2

Affected versions
>=0 <=1.5

Milesight

WT211 V2

Affected versions
>=0 <=1.5

Milesight

UC501

Affected versions
>=0 <=1.6

Milesight

UC502

Affected versions
>=0 <=1.6

Milesight

UC511 V4

Affected versions
>=0 <=1.6

Milesight

UC512 V4

Affected versions
>=0 <=1.6

Milesight

UC521 LoRaWAN®

Affected versions
>=0 <=1.2

Milesight

UC521 Cellular

Affected versions
>=0 <=1.3

Milesight

EM300-DI

Affected versions
>=0 <=1.3

Milesight

EM300-MCS V3

Affected versions
>=0 <=1.10

Milesight

EM300-MLD V3

Affected versions
>=0 <=1.10

Milesight

EM300-SLD V3

Affected versions
>=0 <=1.10

Milesight

EM300-ZLD V3

Affected versions
>=0 <=1.10

Milesight

EM320-TILT

Affected versions
>=0 <=1.3

Milesight

EM400-TLD LoRaWAN®

Affected versions
>=0 <=1.2

Milesight

EM400-TLD NB-IoT

Affected versions
>=0 <=1.5

Milesight

EM400-MUD LoRaWAN®

Affected versions
>=0 <=1.2

Milesight

EM400-MUD NB-IoT

Affected versions
>=0 <=1.6

Milesight

EM400-UDL LoRaWAN®

Affected versions
>=0 <=1.2

Milesight

EM410-RDL Cellular

Affected versions
>=0 <=1.1

Milesight

EM411-RDL

Affected versions
>=0 <=1.2

Milesight

EM500-CO2 V2

Affected versions
>=0 <=1.11

Milesight

EM500-SWL

Affected versions
>=0 <=1.11

Milesight

EM500-LGT

Affected versions
>=0 <=1.11

Milesight

EM500-PT100 V2

Affected versions
>=0 <=1.11

Milesight

EM500-PP

Affected versions
>=0 <=1.11

Milesight

EM500-SMTC

Affected versions
>=0 <=1.11

Milesight

EM500-UDL

Affected versions
>=0 <=1.11

Milesight

AT101

Affected versions
>=0 <=1.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 20:22:31 UTC

Technical Analysis

This vulnerability involves the cleartext transmission of sensitive LoRaWAN keys via the NFC interface on affected Milesight AM102/102L V2 devices. An attacker physically near the device can perform an NFC read operation without authentication to extract network session keys (NwkSKey), application session keys (AppSKey), and device-to-device (D2D) keys. Possession of these keys enables decryption of LoRaWAN traffic, frame forgery, injection of falsified sensor data, execution of supported device commands, and rejection of legitimate frames, severely compromising device and network integrity.

Potential Impact

The exposure of LoRaWAN session keys and D2D keys compromises confidentiality and integrity of communications. Attackers can decrypt sensitive data, impersonate devices by forging uplink and downlink frames, inject false sensor readings, and disrupt normal device operations by causing legitimate frames to be rejected. This undermines trust in the IoT network and may lead to operational disruptions or data manipulation.

Mitigation Recommendations

No official patch or remediation is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is provided, physical security controls to prevent unauthorized NFC access are recommended. Avoid placing devices in easily accessible locations and consider disabling NFC if possible. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
mitre
Date Reserved
2026-03-04T16:57:42.093Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a8e5c0eacd9273b495167ca

Added to database: 08/26/2026, 03:22:54 UTC

Last enriched: 09/09/2026, 20:22:31 UTC

Last updated: 10/09/2026, 06:48:16 UTC

Views: 75

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses