🔐 CVE Alert

CVE-2026-29988

HIGH 7.6
CVSS Score
7.6
EPSS Score
0.0%
EPSS Percentile
0th

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

CWE CWE-319
Vendor milesight
Product am102/102l v2
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for milesight am102/102l v2

Be the first to know when new high vulnerabilities affecting milesight am102/102l v2 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Milesight / AM102/102L V2
0 ≤ 1.4
Milesight / AM103/103L V2
0 ≤ 1.8
Milesight / AM304L
0 ≤ 1.2
Milesight / AM305L
0 ≤ 1.2
Milesight / AM307 V2
0 ≤ 1.4
Milesight / AM308
0 ≤ 1.7
Milesight / AM308L
0 ≤ 1.7
Milesight / AM319
0 ≤ 1.6
Milesight / WS101
0 ≤ 1.5
Milesight / WS136
0 ≤ 1.6
Milesight / WS156
0 ≤ 1.6
Milesight / WS201
0 ≤ 1.2
Milesight / WS202
0 ≤ 1.8
Milesight / WS203
0 ≤ 1.3
Milesight / WS301
0 ≤ 1.15
Milesight / WS303
0 ≤ 1.5
Milesight / WS50X (2W-W11-EU) [501/502/503]
0 ≤ 1.3
Milesight / WS50X (3W-W11-EU) [501/502/503]
0 ≤ 1.2
Milesight / WS50X (3W-W12-EU) [501/502/503]
0 ≤ 1.2
Milesight / WS51X [513/515]
0 ≤ 1.9
Milesight / WS52X [523/525]
0 ≤ 1.12
Milesight / WS558
0 ≤ 1.1
Milesight / VS321
0 ≤ 321.1.0.1-r5
Milesight / VS360
0 ≤ 1.2-r1
Milesight / VS350 V3
0 ≤ 1.1
Milesight / VS351
0 ≤ 1.5
Milesight / VS330
0 ≤ 1.3
Milesight / VS340
0 ≤ 1.1
Milesight / VS341
0 ≤ 1.1
Milesight / VS370
0 ≤ 1.1
Milesight / GS301
0 ≤ 1.2
Milesight / EM300-TH V3
0 ≤ 1.10
Milesight / EM320-TH
0 ≤ 1.6
Milesight / TS201 V2
0 ≤ 1.1
Milesight / TS30x V2
0 ≤ 1.1
Milesight / WT201 V2
0 ≤ 1.5
Milesight / WT211 V2
0 ≤ 1.5
Milesight / UC501
0 ≤ 1.6
Milesight / UC502
0 ≤ 1.6
Milesight / UC511 V4
0 ≤ 1.6
Milesight / UC512 V4
0 ≤ 1.6
Milesight / UC521 LoRaWAN®
0 ≤ 1.2
Milesight / UC521 Cellular
0 ≤ 1.3
Milesight / EM300-DI
0 ≤ 1.3
Milesight / EM300-MCS V3
0 ≤ 1.10
Milesight / EM300-MLD V3
0 ≤ 1.10
Milesight / EM300-SLD V3
0 ≤ 1.10
Milesight / EM300-ZLD V3
0 ≤ 1.10
Milesight / EM320-TILT
0 ≤ 1.3
Milesight / EM400-TLD LoRaWAN®
0 ≤ 1.2
Milesight / EM400-TLD NB-IoT
0 ≤ 1.5
Milesight / EM400-MUD LoRaWAN®
0 ≤ 1.2
Milesight / EM400-MUD NB-IoT
0 ≤ 1.6
Milesight / EM400-UDL LoRaWAN®
0 ≤ 1.2
Milesight / EM410-RDL Cellular
0 ≤ 1.1
Milesight / EM411-RDL
0 ≤ 1.2
Milesight / EM500-CO2 V2
0 ≤ 1.11
Milesight / EM500-SWL
0 ≤ 1.11
Milesight / EM500-LGT
0 ≤ 1.11
Milesight / EM500-PT100 V2
0 ≤ 1.11
Milesight / EM500-PP
0 ≤ 1.11
Milesight / EM500-SMTC
0 ≤ 1.11
Milesight / EM500-UDL
0 ≤ 1.11
Milesight / AT101
0 ≤ 1.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
milesight.com: https://www.milesight.com/legal/vulnerabilities-in-some-milesight-sensors