Description
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.
Published: 2026-08-26
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Exposure of cryptographic keys via cleartext NFC transmission
Action: Patch Firmware
AI Analysis

Impact

An insecure transmission (CWE‑319) in the NFC interface of multiple Milesight IoT devices allows an unauthenticated attacker with physical proximity to read sensitive information that is sent in cleartext. The exposed data includes LoRaWAN ABP NwkSKey and AppSKey values as well as device‑to‑device keys. With these keys in hand, an attacker can decrypt encrypted network traffic, forge uplink and downlink frames, inject falsified sensor data, trigger device commands, and cause legitimate frames to be rejected, thereby compromising confidentiality, integrity, and availability of the affected network segment.

Affected Systems

Milesight sensors and gateways—models AM102/102L V2, AM103/103L V2, AM304L, AM305L, AM307 V2, AM308, AM308L, AM319, AT101, EM300 series, EM320 series, EM400 series for LoRaWAN and NB‑IoT, EM410, EM411, EM500 series, GS301, TS201 V2, TS30x V2, UC501, UC502, UC511 V4, UC512 V4, UC521 cellular and LoRaWAN, VS321 through VS360 series, WS101 through WS558 series, WT201 V2, WT211 V2, and other models listed in the vendor advisory. The exact firmware version is not specified, but the flaw exists in the affected firmware versions referenced in the advisory.

Risk and Exploitability

The CVSS score of 8.3 classifies this flaw as high severity. EPSS is not available, indicating uncertainty about the current exploitation rate. The flaw is not listed in the CISA KEV catalog. Attackers must be physically close to the device to perform the NFC read operation, limiting the threat to those who can approach the device in person. Once the keys are captured, however, attackers gain full cryptographic control over the LoRaWAN network segment handled by the device, enabling severe confidentiality loss and availability disruption.

Generated by OpenCVE AI on August 26, 2026 at 04:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest release that fixes the cleartext NFC transmission flaw
  • If no update is available, disable or block physical access to the device’s NFC interface until a patch arrives
  • After patching or disabling NFC, regenerate and deploy new LoRaWAN ABP NwkSKey, AppSKey, and device‑to‑device keys to replace any that may have been compromised

Generated by OpenCVE AI on August 26, 2026 at 04:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cleartext NFC Transmission of LoRaWAN and D2D Keys in Milesight IoT Devices

Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Description A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-26T15:29:07.675Z

Reserved: 2026-03-04T16:57:42.093Z

Link: CVE-2026-29988

cve-icon Vulnrichment

Updated: 2026-08-26T15:29:03.807Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T05:18:07.543

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-29988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T05:00:12Z

Weaknesses
  • CWE-319

    Cleartext Transmission of Sensitive Information