top of page
perceptive_background_267k.jpg

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Published:

27 april 2026 om 22:00:00

Alert date:

28 april 2026 om 21:20:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

Specific firmware versions of Milesight AIOT cameras contain a critical vulnerability where SSL certificates are configured with default private keys. This security flaw allows attackers to potentially intercept and decrypt SSL/TLS communications intended to be secure. The vulnerability affects multiple firmware versions across Milesight's AIOT camera product line. CISA has issued an advisory (ICSA-26-113-03) regarding this issue. Organizations using affected Milesight AIOT cameras should update to patched firmware versions immediately. The use of default cryptographic keys represents a fundamental security weakness that can be exploited for man-in-the-middle attacks.

Technical details

Mitigation steps:

Affected products:

Milesight AIOT cameras

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page