CVE Tools

Milesight

80 CVEs tracked since 2019. Since Oct 2019, none of them reached CISA KEV.

Milesight CVEs per month

Oct 2019 to Jun 2024. Point at a month, or focus the strip and use the arrow keys.
Milesight CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2019-1050
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07690
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-0660

Products

The products that kept showing up in Milesight's monthly top three, with their CVEs summed over those months.

  1. UR32L631 month
  2. UR32L Firmware631 month
  3. Devicehub61 month
  4. Milesight Devicehub61 month
  5. Milesightvpn61 month
  6. Ip Security Camera Firmware51 month
  7. Ip Security Cameras51 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Milesight.

  1. CVE-2026-29988A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker wi...7.6
  2. CVE-2026-20766Milesight Cameras Heap-based Buffer Overflow8.8
  3. CVE-2026-32649Milesight Cameras OS Command Injection6.8
  4. CVE-2026-32644Milesight Cameras Use of Hard-coded Cryptographic Key9.8
  5. CVE-2026-27785Milesight Cameras Use of Hard-coded Credentials8.8
  6. CVE-2026-28747Milesight Cameras Authorization Bypass Through User-Controlled Key7.1
  7. CVE-2025-4043Milesight UG65-868M-EA Improper Access Control for Volatile Memory Containing Boot Code6.8
  8. CVE-2024-36392MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6.1
  9. CVE-2024-36391MileSight DeviceHub - CWE-320: Key Management Errors9.1
  10. CVE-2024-36390MileSight DeviceHub - CWE-20 Improper Input Validation7.5
  11. CVE-2024-36389MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values9.8
  12. CVE-2024-36388MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function10.0
  13. CVE-2024-27776MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9.8
  14. CVE-2023-47166A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attac...8.8
  15. CVE-2023-43260Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.6.1

The record

Peak rank
#10 in Jul 2023
Busiest month shown
Jul 2023, 69 CVEs
Months with a KEV entry
0 since Oct 2019
Monthly snapshots
3 since 2019
Milesight's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store