Sceawere

Vulnerability Detail

CVE-2026-29988UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Milesight NFC Sensitive Data Exposure

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
14h ago
Vendor
Milesight
Product
AM102/102L V2
Attack Type
CWE-319: Cleartext Transmission of Sensitive Information
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-08-26T05:18:07.543Z",
  "pubdate": "2026-08-26T05:18:07.543Z",
  "executiveSummary": "This vulnerability involves the cleartext transmission of sensitive cryptographic material via the Near Field Communication (NFC) interface in multiple Milesight IoT device models. The security flaw allows an unauthenticated, physically proximate attacker to extract critical LoRaWAN session keys, specifically the Network Session Key (NwkSKey) and the Application Session Key (AppSKey), as well as device-to-device (D2D) communication keys.\nThe exposure of these cryptographic assets represents a critical security failure, as they underpin the integrity, confidentiality, and authenticity of LoRaWAN communications. By leveraging the NFC interface, an attacker can bypass traditional network-layer security controls. The compromise of these keys enables the decryption of captured traffic and facilitates the injection of malicious frames, which can result in the complete subversion of sensor data and unauthorized command execution. This vulnerability necessitates physical proximity, yet it poses significant risk to environments where device tamper-proofing or physical site security is insufficient. The inability to protect session-specific cryptographic material directly undermines the entire security posture of the affected LoRaWAN ecosystem.",
  "technicalDetails": "The vulnerability originates from the insecure implementation of the NFC communication protocol within the affected Milesight IoT device firmware, which fails to enforce adequate access control or encryption for sensitive data stored in device memory. During an NFC read operation, the firmware exposes the LoRaWAN ABP (Activation By Personalization) credentials and D2D keys in cleartext, accessible to any unauthorized NFC-compliant reader device.\nThe exploitation flow begins with the attacker establishing physical proximity to the target device. Using a standard NFC-enabled mobile device or a specialized NFC reader, the attacker performs a read request against the Milesight device's NFC interface. Because the device lacks authentication requirements or a secure element-backed challenge-response mechanism for NFC data access, it responds to the request by broadcasting the NwkSKey, AppSKey, and D2D keys. This process requires no prior knowledge of credentials, as the interface treats the read request as a trusted operation.\nOnce the session keys are harvested, the attacker gains the capability to perform man-in-the-middle (MitM) attacks or direct message injection. Since the NwkSKey is used for calculating the Message Integrity Code (MIC) and the AppSKey is used for payload encryption/decryption, the attacker can decrypt historical and future traffic intercepted over the LoRaWAN radio interface. Furthermore, by calculating the correct MIC using the extracted keys, the attacker can forge legitimate-looking uplink packets to inject falsified sensor data into the network application server, or issue unauthorized downlink commands to the device. The ability to manipulate the frame counter sequence using these keys further allows the attacker to cause desynchronization, leading to the rejection of legitimate subsequent frames, effectively resulting in a permanent denial-of-service (DoS) or spoofing condition at the application layer. The vulnerability affects multiple Milesight IoT models that utilize NFC for configuration, highlighting a failure to implement proper cryptographic protections or data masking during the transmission of sensitive key material through secondary out-of-band communication channels."
}
CVE-2026-29988: Milesight NFC Sensitive Data Exposure (HIGH Severity, CVSS: 7.6) - Sceawere