Date:2026-07-15
At Milesight, we take product security seriously. As part of our ongoing commitment to safeguarding users and systems, we continuously monitor for potential vulnerabilities and act swiftly to mitigate risks.
Recent internal security reviews, supplemented by external reports, have identified a vulnerability in specific firmware versions of Milesight IoT products.
A security vulnerability has been identified that when an attacker uses NFC-enabled tools to read Milesight devices physically, the ABP keys and D2D keys are transmitted in plaintext. An unauthorized attacker can obtain the ABP nwkskey, appskey and D2D keys via NFC reading, and further launch subsequent attacks.
The attacker needs physical access to the device and uses specific NFC tools to retrieve key information.
Devices deployed in public areas or locations without physical access control. Additionally, devices using ABP mode or D2D function.
1. Devices working in OTAA mode (NFC transmission is encrypted and cannot be intercepted)
2. Devices with strict physical access restrictions, physical access to the device is not possible without authorization.
3. Devices that do not adopt ABP activation mode or enable D2D function.
1. Sensitive key information leakage via NFC plaintext transmission.
2. Attackers can remotely monitor and decrypt device data with stolen keys.
3. Attackers can tamper with device transmitted data.
4. Attackers may send unauthorized commands to D2D terminals and perform illegal operations.
If your device is within the scope of the vulnerability, since the fixed versions have not yet been fully released,if possible, we recommend implementing physical access restrictions at the locations where your devices are deployed to prevent the devices from being easily accessed and to mitigate the vulnerability exploitation risk.
If your devices are deployed in public areas where physical access restrictions cannot be implemented, and are using ABP or D2D functionality, we recommend that you take the following temporary measures to reduce the risk of this vulnerability being exploited:
1. Switch Device from ABP Mode to OTAA Mode (Recommended)
(1) You can change the join type via local Toolbox or remote downlink command:
Local setting: Access Toolbox > Device > Network > LoRaWAN®, set Join Type to OTAA.
Remote downlink command to switch OTAA: 7e050900500101017e
(2) Please delete the old ABP configuration on Network Server, re-add the device with OTAA profile, and restart the device via Toolbox to re-join the network.
2. Temporarily Disable D2D Function
You can disable D2D function via local Toolbox or remote downlink command:
(1) Local setting: Disable D2D function via Toolbox device configuration page.
(2) Remote downlink command to disable D2D: 7e05090050f501007e
Note: Reference command to enable D2D: 7e05090050f501017e
Default D2D Key: 5572404C696E6B4C6F52613230313823
Milesight is developing patched firmware for affected product series in batches:
1. Most models will be fixed before July 30, 2026 or before October 30, 2026.
2. Partial models will be fixed before December 30, 2026.
We recommend you upgrade timely once the fixed firmware is available.
| Product Series | Model | Affected Versions | Notes | Estimated Fix Time | Download Link |
|---|---|---|---|---|---|
| AM-Series | AM102/102L V2 | v1.4 and earlier | before October 30, 2026. | ||
| AM103/103L V2 | v1.8 and earlier | before October 30, 2026. | |||
| AM304L | v1.2 and earlier | before October 30, 2026. | |||
| AM305L | v1.2 and earlier | before October 30, 2026. | |||
| AM307 V2 | v1.4 and earlier | before October 30, 2026. | |||
| AM308 | v1.7 and earlier | before October 30, 2026. | |||
| AM308L | v1.7 and earlier | before October 30, 2026. | |||
| AM319 | v1.6 and earlier | before October 30, 2026. | |||
| WS-Series | WS101 | v1.5 and earlier | before October 30, 2026. | ||
| WS136 | v1.6 and earlier | before October 30, 2026. | |||
| WS156 | v1.6 and earlier | before October 30, 2026. | |||
| WS201 | v1.2 and earlier | before October 30, 2026. | |||
| WS202 | v1.8 and earlier | before October 30, 2026. | |||
| WS203 | v1.3 and earlier | before October 30, 2026. | |||
| WS301 | v1.15 and earlier | before October 30, 2026. | |||
| WS303 | v1.5 and earlier | before October 30, 2026. | |||
| WS50X (2W-W11-EU) 【501/502/503】 | v1.3 and earlier | before October 30, 2026. | |||
| WS50X (3W-W11-EU) 【501/502/503】 | v1.2 and earlier | before October 30, 2026. | |||
| WS50X (3W-W12-EU) 【501/502/503】 | v1.2 and earlier | before October 30, 2026. | |||
| WS51X【513/515】 | v1.9 and earlier | before October 30, 2026. | |||
| WS52X【523/525】 | v1.12 and earlier | before October 30, 2026. | |||
| WS558 | v1.1 and earlier | before October 30, 2026. | |||
| VS-Series | VS321 | v321.1.0.1-r5 and earlier | v321.1.0.1-r6 | Download | |
| VS360 | v1.2-r1 and earlier | before December 30, 2026. | |||
| VS350 V3 | v1.1 and earlier | Currently not available on the official website | before December 30, 2026. | ||
| VS351 | v1.5 and earlier | before December 30, 2026. | |||
| VS330 | v1.3 and earlier | before December 30, 2026. | |||
| VS340 | v1.1 and earlier | before December 30, 2026. | |||
| VS341 | v1.1 and earlier | before December 30, 2026. | |||
| VS370 | v1.1 and earlier | before December 30, 2026. | |||
| GS-Series | GS301 | v1.2 and earlier | before December 30, 2026. | ||
| TH-Series | EM300-TH V3 | v1.10 and earlier | V1.11 | Download | |
| EM320-TH | v1.6 and earlier | v1.8 | Download | ||
| TS-Series | TS201 V2 | v1.1 and earlier | before December 30, 2026. | ||
| TS30x V2 | v1.1 and earlier | v1.2 | Download | ||
| WT-Series | WT201 V2 | v1.5 and earlier | before September 30, 2026. | ||
| WT211 V2 | v1.5 and earlier | before September 30, 2026. | |||
| UC-Series | UC501 | v1.6 and earlier | before December 30, 2026. | ||
| UC502 | v1.6 and earlier | before December 30, 2026. | |||
| UC511 V4 | v1.6 and earlier | v1.7 | Download | ||
| UC512 V4 | v1.6 and earlier | v1.7 | Download | ||
| UC521 LoRaWAN® | v1.2 and earlier | Currently not available on the official website | before December 30, 2026. | ||
| UC521 Cellular | v1.3 and earlier | Currently not available on the official website | before December 30, 2026. | ||
| EM-Series | EM300-DI | v1.3 and earlier | before December 30, 2026. | ||
| EM300-MCS V3 | v1.10 and earlier | v1.11 | Download | ||
| EM300-MLD V3 | v1.10 and earlier | v1.11 | Download | ||
| EM300-SLD V3 | v1.10 and earlier | v1.11 | Download | ||
| EM300-ZLD V3 | v1.10 and earlier | v1.11 | Download | ||
| EM320-TILT | v1.3 and earlier | before December 30, 2026. | |||
| EM400-TLD LoRaWAN® | v1.2 and earlier | before December 30, 2026. | |||
| EM400-TLD NB-IoT | v1.5 and earlier | before December 30, 2026. | |||
| EM400-MUD LoRaWAN® | v1.2 and earlier | before December 30, 2026. | |||
| EM400-MUD NB-IoT | v1.6 and earlier | before December 30, 2026. | |||
| EM400-UDL LoRaWAN® | v1.2 and earlier | before December 30, 2026. | |||
| EM410-RDL Cellular | v1.1 and earlier | before December 30, 2026. | |||
| EM411-RDL | v1.2 and earlier | before December 30, 2026. | |||
| EM500-CO2 V2 | v1.11 and earlier | before July 30, 2026. | |||
| EM500-SWL | v1.11 and earlier | before July 30, 2026. | |||
| EM500-LGT | v1.11 and earlier | before July 30, 2026. | |||
| EM500-PT100 V2 | v1.11 and earlier | before July 30, 2026. | |||
| EM500-PP | v1.11 and earlier | before July 30, 2026. | |||
| EM500-SMTC | v1.11 and earlier | before July 30, 2026. | |||
| EM500-UDL | v1.11 and earlier | before July 30, 2026. | |||
| AT-Series | AT101 | v1.2 and earlier | before December 30, 2026. |
Milesight takes product security very seriously. We apologize for any inconvenience caused by this vulnerability. If you need any technical support or have further questions, please feel free to contact our team.
We encourage all users and partners to report potential security vulnerabilities to help us maintain the integrity of Milesight products.
Please submit reports using the following format:
If you are interested in Milesight, please leave us a message.
Contact Us
Contact Us
Contact Us to Get More Information