CVE-2026-27785

8.8

Milesight · AIOT camera

Milesight AIOT camera firmware contains hard-coded credentials, which could allow unauthorized access to the device.

Executive summary

Several Milesight AIOT camera models contain hard-coded credentials that present a significant risk of unauthorized administrative access and full device compromise.

Vulnerability

The device firmware contains hard-coded credentials (CWE-798), which can be exploited by an unauthenticated attacker on the adjacent network to gain full control over the camera.

Business impact

The presence of hard-coded credentials introduces a severe security risk, as it allows attackers to bypass standard authentication mechanisms entirely. Successful exploitation could lead to full unauthorized access to the camera video feed, device settings, and potential integration into a botnet, posing significant privacy and operational risks. With a CVSS score of 8.8, this vulnerability is considered High severity, warranting immediate attention from security teams.

Remediation

Immediate Action: Update affected devices to the patched firmware versions (e.g., 51.7.0.77-r13 for most models or 3x.8.0.3-r13 for the MS-Cxx74-PA) immediately as provided by the Milesight support portal.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts or unusual login patterns originating from internal or adjacent network segments.

Compensating Controls: Isolate affected cameras on a dedicated, non-routable VLAN and employ firewall rules to restrict access to the web management interface to trusted management workstations only.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a critical failure in credential management that directly exposes the device to unauthorized control. IT administrators must prioritize the firmware update process for all affected Milesight camera units. If immediate patching is not feasible, network-level segmentation is essential to contain the risk until the vendor-supplied security updates can be deployed.

Sources

Originally found and disclosed by Souvik Kandar reported these vulnerabilities to CISA, per the CVE Program record.