Junglewise Threat Intelligence

CVE-2026-32649: Milesight Cameras command injection in web server

CVE-2026-32649 · Severity: medium · CVSS 6.8 · Published 2026-04-28

Technologies: Milesight,versions: MS-Cxx52-xxxPE.

Executive brief

A security vulnerability has been identified in the web server of various Milesight network cameras. These cameras are used for physical security and surveillance in commercial and industrial environments. If exploited, an attacker could gain full control over the camera, potentially leading to unauthorized surveillance, data theft, or a complete shutdown of the security system.

Technical details

A command injection vulnerability (CWE-78) exists within the web server component of multiple Milesight camera firmware versions. The flaw allows an attacker to execute arbitrary OS commands on the device. Exploitation requires network reachability and high privileges (PR:H), along with some level of user interaction (UI:R). Successful exploitation can result in remote code execution or a complete system crash, impacting the confidentiality, integrity, and availability of the device. Users are advised to update to the latest firmware versions provided by Milesight.

Affected products

  • Milesight MS-Cxx63-PD <=51.7.0.77-r12
  • Milesight MS-Cxx64-xPD <=51.7.0.77-r12
  • Milesight MS-Cxx73-xPD <=51.7.0.77-r12
  • Milesight MS-Cxx75-xxPD <=51.7.0.77-r12
  • Milesight MS-Cxx83-xPD <=51.7.0.77-r12
  • Milesight MS-Cxx74-PA <=3x.8.0.3-r11
  • Milesight MS-C8477-HPG1 <=63.8.0.4-r3
  • Milesight MS-C8477-PC <=48.8.0.4-r3
  • Milesight MS-C5321-FPE <=62.8.0.4-r5
  • Milesight MS-Cxx72-xxxPE <=61.8.0.5-r2
  • Milesight MS-Cxx62-xxxPE <=61.8.0.5-r2
  • Milesight,versions: MS-Cxx52-xxxPE

Timeline

  • 2026-04-23: advisory: CISA ICS Advisory ICSA-26-113-03 published
  • 2026-04-28: disclosed: CVE published to NVD

References