Executive brief
Milesight IoT sensors (environmental monitors and gateways) transmit LoRaWAN encryption keys and device-to-device credentials in cleartext over NFC, allowing an attacker with physical access to read and steal these keys. An attacker equipped with NFC tools can extract keys from devices deployed in public areas, decrypt sensor data, impersonate devices on the LoRaWAN network, send unauthorized commands, and disrupt legitimate communications.
Technical details
The vulnerability is a cleartext transmission of sensitive information flaw in the NFC interface of Milesight IoT sensors. When NFC is used to communicate with affected devices, LoRaWAN Activation by Personalization (ABP) keys—specifically the NwkSKey (network session key) and AppSKey (application session key)—along with Device-to-Device (D2D) keys are transmitted without encryption. An unauthenticated attacker with physical proximity and NFC-capable tools can read these credentials directly via NFC. Once obtained, the attacker can decrypt LoRaWAN network traffic, forge uplink and downlink frames, submit falsified sensor data, issue device commands via D2D, and cause legitimate frames to be rejected. The vulnerability only affects devices operating in ABP mode or with D2D functionality enabled; devices using Over-the-Air Activation (OTAA) are unaffected as their NFC transmission is encrypted. Milesight has committed to firmware patches by October 30, 2026 for most models and December 30, 2026 for partial models; interim mitigations include switching to OTAA mode or disabling D2D functionality.
Affected products
- Milesight AM102/102L V2 v1.4 and earlier
- Milesight AM103/103L V2 v1.8 and earlier
- Milesight AM304L v1.2 and earlier
- Milesight AM305L v1.2 and earlier
- Milesight AM307 V2 v1.4 and earlier
- Milesight AM308 v1.7 and earlier
- Milesight AM308L v1.7 and earlier
- Milesight AM319 v1.6 and earlier
- Milesight WS101 v1.5 and earlier
- Milesight WS136 v1.6 and earlier
- Milesight WS156 v1.6 and earlier
- Milesight WS201 v1.2 and earlier
- Milesight WS202 v1.8 and earlier
- Milesight WS203 v1.3 and earlier
- Milesight WS301 v1.15 and earlier
- Milesight WS303 v1.5 and earlier
- Milesight WS50X 501/502/503 (2W-W11-EU) v1.3 and earlier
- Milesight WS50X 501/502/503 (3W-W11-EU) v1.2 and earlier
- Milesight WS50X 501/502/503 (3W-W12-EU) v1.2 and earlier
- Milesight WS51X 513/515 v1.9 and earlier
Timeline
- 2026-07-15: disclosed: Vulnerability advisory published by Milesight
- 2026-08-26: advisory: CVE-2026-29988 published on NVD