PT-2026-81924 · Milesight · Am102/102L V2+63

CVE-2026-80216

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The exposed keys can be used to decrypt LoRaWAN traffic, forge uplink and downlink frames, submit falsified sensor data, issue supported device commands, and cause subsequent legitimate frames to be rejected.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-80216

Affected Products

Am102/102L V2
Am103/103L V2
Am304L
Am305L
Am307 V2
Am308
Am308L
Am319
At101
Em300-Di
Em300-Mcs V3
Em300-Mld V3
Em300-Sld V3
Em300-Th V3
Em300-Zld V3
Em320-Th
Em320-Tilt
Em400-Mud Lorawan®
Em400-Mud Nb-Iot
Em400-Tld Lorawan®
Em400-Tld Nb-Iot
Em400-Udl Lorawan®
Em410-Rdl Cellular
Em411-Rdl
Em500-Co2 V2
Em500-Lgt
Em500-Pp
Em500-Pt100 V2
Em500-Smtc
Em500-Swl
Em500-Udl
Gs301
Ts201 V2
Ts30X V2
Uc501
Uc502
Uc511 V4
Uc512 V4
Uc521 Cellular
Uc521 Lorawan®
Vs321
Vs330
Vs340
Vs341
Vs350 V3
Vs351
Vs360
Vs370
Ws101
Ws136
Ws156
Ws201
Ws202
Ws203
Ws301
Ws303
Ws50X (2W-W11-Eu) [501/502/503]
Ws50X (3W-W11-Eu) [501/502/503]
Ws50X (3W-W12-Eu) [501/502/503]
Ws51X [513/515]
Ws52X [523/525]
Ws558
Wt201 V2
Wt211 V2