---
id: CVE-2026-29988
title: >-
  A cleartext transmission of sensitive information vulnerability in the NFC
  interface of multiple Milesight IoT device models running affected firmware
  versions allows an unauthenticated attacker with physical proximity to
  retrieve LoRaWA…
summary: >-
  A cleartext transmission of sensitive information vulnerability in the NFC
  interface of multiple Milesight IoT device models running affected firmware
  versions allows an unauthenticated attacker with physical proximity to
  retrieve LoRaWA…
severity: high
cvss: 7.6
cvssVector: 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-319
published: '2026-08-26'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T16:04:24.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-29988'
references:
  - url: 'https://www.milesight.com/legal/vulnerabilities-in-some-milesight-sensors'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00166
epssPercentile: 0.05165
ingestedAt: '2026-09-09T16:14:05.515Z'
---

## Overview

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
