Impact
An insecure transmission (CWE‑319) in the NFC interface of multiple Milesight IoT devices allows an unauthenticated attacker with physical proximity to read sensitive information that is sent in cleartext. The exposed data includes LoRaWAN ABP NwkSKey and AppSKey values as well as device‑to‑device keys. With these keys in hand, an attacker can decrypt encrypted network traffic, forge uplink and downlink frames, inject falsified sensor data, trigger device commands, and cause legitimate frames to be rejected, thereby compromising confidentiality, integrity, and availability of the affected network segment.
Affected Systems
Milesight sensors and gateways—models AM102/102L V2, AM103/103L V2, AM304L, AM305L, AM307 V2, AM308, AM308L, AM319, AT101, EM300 series, EM320 series, EM400 series for LoRaWAN and NB‑IoT, EM410, EM411, EM500 series, GS301, TS201 V2, TS30x V2, UC501, UC502, UC511 V4, UC512 V4, UC521 cellular and LoRaWAN, VS321 through VS360 series, WS101 through WS558 series, WT201 V2, WT211 V2, and other models listed in the vendor advisory. The exact firmware version is not specified, but the flaw exists in the affected firmware versions referenced in the advisory.
Risk and Exploitability
The CVSS score of 8.3 classifies this flaw as high severity. EPSS is not available, indicating uncertainty about the current exploitation rate. The flaw is not listed in the CISA KEV catalog. Attackers must be physically close to the device to perform the NFC read operation, limiting the threat to those who can approach the device in person. Once the keys are captured, however, attackers gain full cryptographic control over the LoRaWAN network segment handled by the device, enabling severe confidentiality loss and availability disruption.
OpenCVE Enrichment