Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Milesight — Vulnerabilities & Security Advisories 92

Browse all 92 CVE security advisories affecting Milesight. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Milesight operates primarily in the Internet of Things sector, manufacturing IoT sensors, gateways, and video surveillance equipment for industrial and commercial applications. Security analysis reveals a significant vulnerability footprint, with 91 Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation, often stemming from inadequate input validation and weak authentication mechanisms in web interfaces. The company’s firmware and web management consoles have repeatedly exhibited insecure default configurations, allowing unauthorized access to sensitive device settings. While specific large-scale public breaches are not widely reported, the high volume of disclosed CVEs indicates systemic weaknesses in the development lifecycle. Users must prioritize regular firmware updates and network segmentation to mitigate risks associated with these known exploitable defects in their IoT infrastructure.

CVE ID Title CVSS Severity Published
CVE-2026-29988 Milesight IoT设备NFC接口密钥明文传输漏洞 — AM102/102L V2 CWE-319 7.6 High 2026-08-26
CVE-2026-20766 Milesight Cameras Heap-based Buffer Overflow — MS-Cxx63-PD CWE-122 8.8 High 2026-04-27
CVE-2026-32649 Milesight Cameras OS Command Injection — MS-Cxx63-PD CWE-78 6.8 Medium 2026-04-27
CVE-2026-32644 Milesight Cameras Use of Hard-coded Cryptographic Key — MS-Cxx63-PD CWE-321 9.8 Critical 2026-04-27
CVE-2026-27785 Milesight Cameras Use of Hard-coded Credentials — MS-Cxx63-PD CWE-798 8.8 High 2026-04-27
CVE-2026-28747 Milesight Cameras Authorization Bypass Through User-Controlled Key — MS-Cxx63-PD CWE-639 7.1 High 2026-04-27
CVE-2025-4043 Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code — UG65-868M-EA CWE-1274 6.8 Medium 2025-05-07
CVE-2024-36392 MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') — DeviceHub CWE-79 6.1 Medium 2024-06-02
CVE-2024-36391 MileSight DeviceHub - CWE-320: Key Management Errors — DeviceHub CWE-320 9.1 Critical 2024-06-02
CVE-2024-36390 MileSight DeviceHub - CWE-20 Improper Input Validation — DeviceHub CWE-20 7.5 High 2024-06-02
CVE-2024-36389 MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values — DeviceHub CWE-330 9.8 Critical 2024-06-02
CVE-2024-36388 MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function — DeviceHub CWE-305 10.0 Critical 2024-06-02
CVE-2024-27776 MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — DeviceHub CWE-22 9.8 Critical 2024-06-02
CVE-2023-47166 Milesight UR32L 授权问题漏洞 — UR32L CWE-285 8.8 High 2024-05-01
CVE-2023-23550 Milesight UR32L 操作系统操作系统命令注入漏洞 — UR32L CWE-77 7.2 High 2023-07-06
CVE-2023-23547 Milesight UR32L 路径遍历漏洞 — UR32L CWE-22 6.5 Medium 2023-07-06
CVE-2023-23571 Milesight UR32L 安全漏洞 — UR32L CWE-126 7.5 High 2023-07-06
CVE-2023-22659 Milesight UR32L 操作系统命令注入漏洞 — UR32L CWE-77 7.2 High 2023-07-06
CVE-2023-23902 Milesight UR32L 安全漏洞 — UR32L CWE-121 9.8 Critical 2023-07-06
CVE-2023-22306 Milesight UR32L 命令注入漏洞 — UR32L CWE-77 7.2 High 2023-07-06
CVE-2023-22844 Milesight VPN 安全漏洞 — MilesightVPN CWE-321 7.3 High 2023-07-06
CVE-2023-22319 Milesight VPN SQL注入漏洞 — MilesightVPN CWE-89 7.3 High 2023-07-06
CVE-2023-23907 Milesight VPN 路径遍历漏洞 — MilesightVPN CWE-22 7.5 High 2023-07-06
CVE-2023-22371 Milesight VPN 操作系统命令注入漏洞 — MilesightVPN CWE-77 8.1 High 2023-07-06
CVE-2023-23546 Milesight UR32L 信任管理问题漏洞 — UR32L CWE-295 4.2 Medium 2023-07-06
CVE-2023-24496 Milesight VPN 安全漏洞 — MilesightVPN CWE-80 4.7 Medium 2023-07-06
CVE-2023-24497 Milesight VPN 安全漏洞 — MilesightVPN CWE-80 4.7 Medium 2023-07-06
CVE-2023-24520 Milesight UR32L 操作系统命令注入漏洞 — UR32L CWE-77 8.8 High 2023-07-06
CVE-2023-24582 Milesight UR32L 操作系统命令注入漏洞 — UR32L CWE-77 8.8 High 2023-07-06
CVE-2023-24519 Milesight UR32L 操作系统命令注入漏洞 — UR32L CWE-77 8.8 High 2023-07-06

This page lists every published CVE security advisory associated with Milesight. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.