CVE-2026-32644

Received
Published: 27 Apr 2026, 23:40
Last modified:27 Apr 2026, 23:40

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Apr 2026, 23:40
Published
Vulnerability first disclosed

Description

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

CVSS Metrics

  • v4.0CRITICALScore: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v4.0CRITICALScore: 9.2CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Techniques & Countermeasures

  • CWE-321Use of Hard-coded Cryptographic Key

    The product uses a hard-coded, unchangeable cryptographic key.

Affected Systems

  • milesightms-c2964-rflpc

    ≤ T_45.8.0.3-r9

  • milesightms-c2966-rflwpc

    ≤ T_45.8.0.3-r9

  • milesightms-c2966-x12rlpc

    ≤ T_45.8.0.3-r9

  • milesightms-c2966-x12rlvpc

    ≤ T_45.8.0.3-r9

  • milesightms-c2972-rflpc

    ≤ T_45.8.0.3-r9

  • milesightms-c5321-fpe

    ≤ 62.8.0.4-r5

  • milesightms-c5361-x12lpc

    ≤ T_45.8.0.3-r9

  • milesightms-c5366-x12lpc

    ≤ T_45.8.0.3-r9

  • milesightms-c5366-x12lvpc

    ≤ T_45.8.0.3-r9

  • milesightms-c8477-hpg1

    ≤ 63.8.0.4-r3

  • milesightms-c8477-pc

    ≤ 48.8.0.4-r3

  • milesightms-cqxx31-xxxg1

    ≤ CQ_63.8.0.5-r1

  • milesightms-cqxx68-xxxg1

    ≤ CQ_63.8.0.5-r1

  • milesightms-cqxx72-xxxg1

    ≤ CQ_63.8.0.5-r1

  • milesightms-cxx41-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx52-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx61-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx62-xxxg1

    ≤ 63.8.0.5-r3

  • milesightms-cxx62-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx63-pd

    ≤ 51.7.0.77-r12

  • milesightms-cxx64-xpd

    ≤ 51.7.0.77-r12

  • milesightms-cxx65-pe

    ≤ 61.8.0.5-r2

  • milesightms-cxx66-fipkg1

    ≤ 63.8.0.4-r1-NX

  • milesightms-cxx66-rfipkg1

    ≤ 63.8.0.4-r1-NX

  • milesightms-cxx66-xxxg1

    ≤ 63.8.0.5-r3

  • milesightms-cxx66-xxxgpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx66-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx66-xxxxgopc

    ≤ 45.8.0.2-AIoT-r4

  • milesightms-cxx67-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx71-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx72-fipkg1

    ≤ 63.8.0.4-r1-NX

  • milesightms-cxx72-rfipkg1

    ≤ 63.8.0.4-r1-NX

  • milesightms-cxx72-xxxg1

    ≤ 63.8.0.5-r3

  • milesightms-cxx72-xxxpe

    ≤ 61.8.0.5-r2

  • milesightms-cxx73-xpd

    ≤ 51.7.0.77-r12

  • milesightms-cxx74-pa

    ≤ 3x.8.0.3-r11

  • milesightms-cxx75-xxpd

    ≤ 51.7.0.77-r12

  • milesightms-cxx76-pe

    ≤ 61.8.0.5-r2

  • milesightms-cxx83-xpd

    ≤ 51.7.0.77-r12

  • milesightms-nxxxx-nxe

    ≤ 7x.9.0.19-r5

  • milesightms-nxxxx-xxc

    ≤ 7x.9.0.19-r5

  • milesightms-nxxxx-xxe

    ≤ 7x.9.0.19-r5

  • milesightms-nxxxx-xxg

    ≤ 7x.9.0.19-r5

  • milesightms-nxxxx-xxh

    ≤ 7x.9.0.19-r5

  • milesightms-nxxxx-xxt

    ≤ 7x.9.0.19-r5

  • milesightpm3322-e

    ≤ PI_61.8.0.3_LPR-r3

  • milesightpmc8266-fgpe

    ≤ PO_61.8.0.4_LPR

  • milesightpmc8266-fpe

    ≤ PO_61.8.0.4_LPR

  • milesightsc211

    ≤ C_21.1.0.8-r4

  • milesightsp111

    ≤ 52.8.0.4-r5

Showing first 50 affected entries in server-rendered view.

References (3)