PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-29988 Milesight CVE debrief

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. This vulnerability enables the attacker to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, and issue supported device commands. Defenders responsible for IoT device security, especially those using Milesight IoT devices with NFC interfaces, should assess exposure and prioritize remediation to prevent unauthorized access to sensitive.

Vendor
Milesight
Product
AM102/102L V2
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Defenders responsible for IoT device security, especially those using Milesight IoT devices with NFC interfaces, should assess exposure and prioritize remediation to prevent unauthorized access to sensitive information.

Why it matters

Defenders should care about CVE-2026-29988 because it allows unauthorized access to sensitive information, potentially leading to decryption of LoRaWAN traffic, forgery of frames, and manipulation of sensor data, affecting IoT device security, especially in Milesight IoT deployments with NFC interfaces.

  • Decrypt LoRaWAN traffic using exposed keys
  • Forge uplink and downlink frames using exposed keys
  • Submit falsified sensor data using exposed keys
  • Issue supported device commands using exposed keys

Technical summary

The vulnerability allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. This enables the attacker to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, and issue supported device commands. The affected Milesight IoT devices' NFC interface allows unauthorized access to sensitive information, emphasizing the need for secure key management and monitoring for unauthorized access to sensitive information.

Defensive priority

Defenders should prioritize verifying and remediating affected Milesight IoT devices, especially those with NFC interfaces, to prevent unauthorized access to sensitive information.

Recommended defensive actions

  • Verify and remediate affected Milesight IoT devices with NFC interfaces
  • Implement secure key management and storage for LoRaWAN ABP NwkSKey and AppSKey values and D2D keys
  • Monitor for unauthorized access to sensitive information
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the exact affected firmware versions and device models require verification from the vendor or official sources. The Milesight IoT devices' NFC interface allows unauthorized access to sensitive information, including LoRaWAN ABP NwkSKey and AppSKey values and D2D keys. Defenders should verify and remediate affected devices, implement secure key management, and monitor for unauthorized access.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-29988 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-29988

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-29988 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-29988

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.