CVE-2026-29988: CWE-319: Cleartext Transmission of Sensitive Information in Milesight AM102/102L V2
Description
CVE-2026-29988 is a high-severity vulnerability affecting the NFC interface of multiple Milesight AM102/102L V2 IoT devices. It allows an unauthenticated attacker with physical proximity to retrieve sensitive LoRaWAN keys transmitted in cleartext. These keys include NwkSKey, AppSKey, and D2D keys, which can be exploited to decrypt traffic, forge frames, submit false data, and disrupt legitimate communications.
CVSS v4.0
Score 8.3high
Affected software
Milesight
AM102/102L V2
Milesight
AM103/103L V2
Milesight
AM304L
Milesight
AM305L
Milesight
AM307 V2
Milesight
AM308
Milesight
AM308L
Milesight
AM319
Milesight
WS101
Milesight
WS136
Milesight
WS156
Milesight
WS201
Milesight
WS202
Milesight
WS203
Milesight
WS301
Milesight
WS303
Milesight
WS50X (2W-W11-EU) [501/502/503]
Milesight
WS50X (3W-W11-EU) [501/502/503]
Milesight
WS50X (3W-W12-EU) [501/502/503]
Milesight
WS51X [513/515]
Milesight
WS52X [523/525]
Milesight
WS558
Milesight
VS321
Milesight
VS360
Milesight
VS350 V3
Milesight
VS351
Milesight
VS330
Milesight
VS340
Milesight
VS341
Milesight
VS370
Milesight
GS301
Milesight
EM300-TH V3
Milesight
EM320-TH
Milesight
TS201 V2
Milesight
TS30x V2
Milesight
WT201 V2
Milesight
WT211 V2
Milesight
UC501
Milesight
UC502
Milesight
UC511 V4
Milesight
UC512 V4
Milesight
UC521 LoRaWAN®
Milesight
UC521 Cellular
Milesight
EM300-DI
Milesight
EM300-MCS V3
Milesight
EM300-MLD V3
Milesight
EM300-SLD V3
Milesight
EM300-ZLD V3
Milesight
EM320-TILT
Milesight
EM400-TLD LoRaWAN®
Milesight
EM400-TLD NB-IoT
Milesight
EM400-MUD LoRaWAN®
Milesight
EM400-MUD NB-IoT
Milesight
EM400-UDL LoRaWAN®
Milesight
EM410-RDL Cellular
Milesight
EM411-RDL
Milesight
EM500-CO2 V2
Milesight
EM500-SWL
Milesight
EM500-LGT
Milesight
EM500-PT100 V2
Milesight
EM500-PP
Milesight
EM500-SMTC
Milesight
EM500-UDL
Milesight
AT101
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves the cleartext transmission of sensitive LoRaWAN keys via the NFC interface on affected Milesight AM102/102L V2 devices. An attacker physically near the device can perform an NFC read operation without authentication to extract network session keys (NwkSKey), application session keys (AppSKey), and device-to-device (D2D) keys. Possession of these keys enables decryption of LoRaWAN traffic, frame forgery, injection of falsified sensor data, execution of supported device commands, and rejection of legitimate frames, severely compromising device and network integrity.
Potential Impact
The exposure of LoRaWAN session keys and D2D keys compromises confidentiality and integrity of communications. Attackers can decrypt sensitive data, impersonate devices by forging uplink and downlink frames, inject false sensor readings, and disrupt normal device operations by causing legitimate frames to be rejected. This undermines trust in the IoT network and may lead to operational disruptions or data manipulation.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Users should monitor vendor advisories for updates. Until a fix is provided, physical security controls to prevent unauthorized NFC access are recommended. Avoid placing devices in easily accessible locations and consider disabling NFC if possible. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-03-04T16:57:42.093Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8e5c0eacd9273b495167ca
Added to database: 08/26/2026, 03:22:54 UTC
Last enriched: 09/09/2026, 20:22:31 UTC
Last updated: 10/09/2026, 06:48:16 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.