


Perceptive Security
SOC/SIEM Consultancy

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Published:
27 April 2026 at 22:00:00
Alert date:
28 April 2026 at 21:20:20
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
Specific firmware versions of Milesight AIOT cameras contain a critical vulnerability where SSL certificates are configured with default private keys. This security flaw allows attackers to potentially intercept and decrypt SSL/TLS communications intended to be secure. The vulnerability affects multiple firmware versions across Milesight's AIOT camera product line. CISA has issued an advisory (ICSA-26-113-03) regarding this issue. Organizations using affected Milesight AIOT cameras should update to patched firmware versions immediately. The use of default cryptographic keys represents a fundamental security weakness that can be exploited for man-in-the-middle attacks.
Technical details
Mitigation steps:
Affected products:
Milesight AIOT cameras
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32644
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-113-03.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-113-03
https://www.milesight.com/support/download/firmware
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
