在多个运行受影响固件版本的 Milesight IoT 设备模型中,其 NFC 接口存在敏感信息明文传输漏洞。具有物理接近能力且无需认证的攻击者,可通过 NFC 读取操作获取 LoRaWAN ABP 模式的 NwkSKey(网络会话密钥)和 AppSKey(应用会话密钥),以及设备间通信(D2D)密钥。这些泄露的密钥可用于解密 LoRaWAN 流量、伪造上行和下行数据帧、提交伪造的传感器数据、下发受支持的设备命令,并导致后续合法数据帧被拒绝。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Milesight | AM102/102L V2 | 0 ~ 1.4 | - |
|
| Milesight | AM103/103L V2 | 0 ~ 1.8 | - |
|
| Milesight | AM304L | 0 ~ 1.2 | - |
|
| Milesight | AM305L | 0 ~ 1.2 | - |
|
| Milesight | AM307 V2 | 0 ~ 1.4 | - |
|
| Milesight | AM308 | 0 ~ 1.7 | - |
|
| Milesight | AM308L | 0 ~ 1.7 | - |
|
| Milesight | AM319 | 0 ~ 1.6 | - |
|
| Milesight | WS101 | 0 ~ 1.5 | - |
|
| Milesight | WS136 | 0 ~ 1.6 | - |
|
| Milesight | WS156 | 0 ~ 1.6 | - |
|
| Milesight | WS201 | 0 ~ 1.2 | - |
|
| Milesight | WS202 | 0 ~ 1.8 | - |
|
| Milesight | WS203 | 0 ~ 1.3 | - |
|
| Milesight | WS301 | 0 ~ 1.15 | - |
|
| Milesight | WS303 | 0 ~ 1.5 | - |
|
| Milesight | WS50X (2W-W11-EU) [501/502/503] | 0 ~ 1.3 | - |
|
| Milesight | WS50X (3W-W11-EU) [501/502/503] | 0 ~ 1.2 | - |
|
| Milesight | WS50X (3W-W12-EU) [501/502/503] | 0 ~ 1.2 | - |
|
| Milesight | WS51X [513/515] | 0 ~ 1.9 | - |
|
| Milesight | WS52X [523/525] | 0 ~ 1.12 | - |
|
| Milesight | WS558 | 0 ~ 1.1 | - |
|
| Milesight | VS321 | 0 ~ 321.1.0.1-r5 | - |
|
| Milesight | VS360 | 0 ~ 1.2-r1 | - |
|
| Milesight | VS350 V3 | 0 ~ 1.1 | - |
|
| Milesight | VS351 | 0 ~ 1.5 | - |
|
| Milesight | VS330 | 0 ~ 1.3 | - |
|
| Milesight | VS340 | 0 ~ 1.1 | - |
|
| Milesight | VS341 | 0 ~ 1.1 | - |
|
| Milesight | VS370 | 0 ~ 1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet