Vulnerabilities in Some Milesight Sensors

Date:2026-07-15

At Milesight, we take product security seriously. As part of our ongoing commitment to safeguarding users and systems, we continuously monitor for potential vulnerabilities and act swiftly to mitigate risks.

Recent internal security reviews, supplemented by external reports, have identified a vulnerability in specific firmware versions of Milesight IoT products.

Risk Overview

A security vulnerability has been identified that when an attacker uses NFC-enabled tools to read Milesight devices physically, the ABP keys and D2D keys are transmitted in plaintext. An unauthorized attacker can obtain the ABP nwkskey, appskey and D2D keys via NFC reading, and further launch subsequent attacks.

Exploitation Prerequisite

The attacker needs physical access to the device and uses specific NFC tools to retrieve key information.

Affected Scenarios

Devices deployed in public areas or locations without physical access control. Additionally, devices using ABP mode or D2D function.

Unaffected Scenarios

1. Devices working in OTAA mode (NFC transmission is encrypted and cannot be intercepted)

2. Devices with strict physical access restrictions, physical access to the device is not possible without authorization.

3. Devices that do not adopt ABP activation mode or enable D2D function.

Vulnerability Impact

1. Sensitive key information leakage via NFC plaintext transmission.

2. Attackers can remotely monitor and decrypt device data with stolen keys.

3. Attackers can tamper with device transmitted data.

4. Attackers may send unauthorized commands to D2D terminals and perform illegal operations.

Next Steps for Users

If your device is within the scope of the vulnerability, since the fixed versions have not yet been fully released,if possible, we recommend implementing physical access restrictions at the locations where your devices are deployed to prevent the devices from being easily accessed and to mitigate the vulnerability exploitation risk.

If your devices are deployed in public areas where physical access restrictions cannot be implemented, and are using ABP or D2D functionality, we recommend that you take the following temporary measures to reduce the risk of this vulnerability being exploited:

1. Switch Device from ABP Mode to OTAA Mode (Recommended)

(1) You can change the join type via local Toolbox or remote downlink command:

Local setting: Access Toolbox > Device > Network > LoRaWAN®, set Join Type to OTAA.

Remote downlink command to switch OTAA: 7e050900500101017e

(2) Please delete the old ABP configuration on Network Server, re-add the device with OTAA profile, and restart the device via Toolbox to re-join the network.

2. Temporarily Disable D2D Function

You can disable D2D function via local Toolbox or remote downlink command:

(1) Local setting: Disable D2D function via Toolbox device configuration page.

(2) Remote downlink command to disable D2D: 7e05090050f501007e

Note: Reference command to enable D2D: 7e05090050f501017e

Default D2D Key: 5572404C696E6B4C6F52613230313823

Firmware Remediation Plan

Milesight is developing patched firmware for affected product series in batches:

1. Most models will be fixed before July 30, 2026 or before October 30, 2026.

2. Partial models will be fixed before December 30, 2026.

We recommend you upgrade timely once the fixed firmware is available.

Affected Products & Estimated Fix Time

Product SeriesModelAffected VersionsNotesEstimated Fix TimeDownload Link
AM-SeriesAM102/102L V2v1.4 and earlierbefore October 30, 2026.
AM103/103L V2v1.8 and earlierbefore October 30, 2026.
AM304Lv1.2 and earlierbefore October 30, 2026.
AM305Lv1.2 and earlierbefore October 30, 2026.
AM307 V2v1.4 and earlierbefore October 30, 2026.
AM308v1.7 and earlierbefore October 30, 2026.
AM308Lv1.7 and earlierbefore October 30, 2026.
AM319v1.6 and earlierbefore October 30, 2026.
WS-SeriesWS101v1.5 and earlierbefore October 30, 2026.
WS136v1.6 and earlierbefore October 30, 2026.
WS156v1.6 and earlierbefore October 30, 2026.
WS201v1.2 and earlierbefore October 30, 2026.
WS202v1.8 and earlierbefore October 30, 2026.
WS203v1.3 and earlierbefore October 30, 2026.
WS301v1.15 and earlierbefore October 30, 2026.
WS303v1.5 and earlierbefore October 30, 2026.
WS50X (2W-W11-EU) 【501/502/503】v1.3 and earlierbefore October 30, 2026.
WS50X (3W-W11-EU) 【501/502/503】v1.2 and earlierbefore October 30, 2026.
WS50X (3W-W12-EU) 【501/502/503】v1.2 and earlierbefore October 30, 2026.
WS51X【513/515】v1.9 and earlierbefore October 30, 2026.
WS52X【523/525】v1.12 and earlierbefore October 30, 2026.
WS558v1.1 and earlierbefore October 30, 2026.
VS-SeriesVS321v321.1.0.1-r5 and earlierDownload
VS360v1.2-r1 and earlierbefore December 30, 2026.
VS350 V3v1.1 and earlierbefore December 30, 2026.
VS351v1.5 and earlierbefore December 30, 2026.
VS330v1.3 and earlierbefore December 30, 2026.
VS340v1.1 and earlierbefore December 30, 2026.
VS341v1.1 and earlierbefore December 30, 2026.
VS370v1.1 and earlierbefore December 30, 2026.
GS-SeriesGS301v1.2 and earlierbefore December 30, 2026.
TH-SeriesEM300-TH V3v1.10 and earlierDownload
EM320-THv1.6 and earlierDownload
TS-SeriesTS201 V2v1.1 and earlierbefore December 30, 2026.
TS30x V2v1.1 and earlierDownload
WT-SeriesWT201 V2v1.5 and earlierbefore September 30, 2026.
WT211 V2v1.5 and earlierbefore September 30, 2026.
UC-SeriesUC501v1.6 and earlierbefore December 30, 2026.
UC502v1.6 and earlierbefore December 30, 2026.
UC511 V4v1.6 and earlierDownload
UC512 V4v1.6 and earlierDownload
UC521 LoRaWAN®v1.2 and earlierbefore December 30, 2026.
UC521 Cellularv1.3 and earlierbefore December 30, 2026.
EM-SeriesEM300-DIv1.3 and earlierbefore December 30, 2026.
EM300-MCS V3v1.10 and earlierDownload
EM300-MLD V3v1.10 and earlierDownload
EM300-SLD V3v1.10 and earlierDownload
EM300-ZLD V3v1.10 and earlierDownload
EM320-TILTv1.3 and earlierbefore December 30, 2026.
EM400-TLD LoRaWAN®v1.2 and earlierbefore December 30, 2026.
EM400-TLD NB-IoTv1.5 and earlierbefore December 30, 2026.
EM400-MUD LoRaWAN®v1.2 and earlierbefore December 30, 2026.
EM400-MUD NB-IoTv1.6 and earlierbefore December 30, 2026.
EM400-UDL LoRaWAN®v1.2 and earlierbefore December 30, 2026.
EM410-RDL Cellularv1.1 and earlierbefore December 30, 2026.
EM411-RDLv1.2 and earlierbefore December 30, 2026.
EM500-CO2 V2v1.11 and earlierbefore July 30, 2026.
EM500-SWLv1.11 and earlierbefore July 30, 2026.
EM500-LGTv1.11 and earlierbefore July 30, 2026.
EM500-PT100 V2v1.11 and earlierbefore July 30, 2026.
EM500-PPv1.11 and earlierbefore July 30, 2026.
EM500-SMTCv1.11 and earlierbefore July 30, 2026.
EM500-UDLv1.11 and earlierbefore July 30, 2026.
AT-SeriesAT101v1.2 and earlierbefore December 30, 2026.

Milesight takes product security very seriously. We apologize for any inconvenience caused by this vulnerability. If you need any technical support or have further questions, please feel free to contact our team.

Reporting Security Issues

We encourage all users and partners to report potential security vulnerabilities to help us maintain the integrity of Milesight products.

Please submit reports using the following format:

If you are interested in Milesight, please leave us a message.

Verify Code

Contact Us

Contact Us

Verify Code

Contact Us to Get More Information