


Perceptive Security
SOC/SIEM Consultancy

Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 01:01:59
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
A security vulnerability has been identified in specific firmware versions of Milesight AIOT cameras containing hard-coded credentials. This vulnerability allows unauthorized access to affected devices through embedded authentication credentials that cannot be changed by users. The issue affects IoT camera systems and poses significant security risks for organizations using these devices. CISA has issued an advisory regarding this vulnerability, indicating its importance for critical infrastructure protection. Organizations using affected Milesight AIOT camera firmware should update to patched versions to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
Milesight AIOT Camera
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27785
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03
https://www.milesight.com/support/download/firmware
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
