विश्लेषण प्रतीक्षितCVE-2026-27785

CVE-2026-27785: Hardcoded Credentials in Milesight AIOT Camera

प्लेटफ़ॉर्म

linux

घटक

milesight-ms-cxx63-pd

CVE-2026-27785 identifies a critical security flaw within Milesight MS-Cxx63-PD AIOT Camera Firmware. This vulnerability stems from the presence of hardcoded credentials, granting attackers potentially unrestricted access to the camera and its associated data. The affected firmware versions include those from 0.0.0 through T63.8.0.4LPR-r3. A firmware update is necessary to resolve this issue.

प्रभाव और हमले की स्थितियाँअनुवाद हो रहा है…

The presence of hardcoded credentials within the Milesight AIOT camera firmware presents a severe security risk. An attacker who discovers these credentials can gain complete control over the camera, including access to live video feeds, recorded footage, and configuration settings. This could lead to unauthorized surveillance, data theft, and potential manipulation of the camera's functionality. Furthermore, compromised cameras can be leveraged as entry points for lateral movement within a network, potentially impacting other connected devices and systems. The blast radius extends to any sensitive data or systems accessible through the camera.

शोषण संदर्भअनुवाद हो रहा है…

CVE-2026-27785 was published on 2026-04-27. The vulnerability's severity is rated HIGH (CVSS: 8.8). There is currently no indication of this vulnerability being actively exploited in the wild. Public proof-of-concept (POC) code is not yet available, but the nature of hardcoded credentials makes it likely that exploits will emerge. Monitor CISA and NVD advisories for updates.

खतरा खुफिया

एक्सप्लॉइट स्थिति

प्रूफ ऑफ कॉन्सेप्टअज्ञात
CISA KEVNO
इंटरनेट एक्सपोज़रमध्यम

EPSS

0.02% (5% शतमक)

CVSS वेक्टर

खतरा इंटेलिजेंस· CVSS 3.1CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H8.8HIGHAttack VectorAdjacentहमलावर लक्ष्य तक कैसे पहुंचता हैAttack ComplexityLowशोषण के लिए आवश्यक शर्तेंPrivileges RequiredNoneहमले के लिए प्रमाणीकरण स्तरUser InteractionNoneक्या पीड़ित को कार्रवाई करनी होगीScopeUnchangedघटक से परे प्रभावConfidentialityHighसंवेदनशील डेटा उजागर होने का जोखिमIntegrityHighअनधिकृत डेटा संशोधन का जोखिमAvailabilityHighसेवा बाधा का जोखिमnextguardhq.com · CVSS v3.1 आधार स्कोर
इन मेट्रिक्स का क्या मतलब है?
Attack Vector
आसन्न — नेटवर्क निकटता आवश्यक: समान LAN, Bluetooth या स्थानीय वायरलेस।
Attack Complexity
निम्न — कोई विशेष शर्त नहीं। विश्वसनीय रूप से शोषण योग्य।
Privileges Required
कोई नहीं — बिना प्रमाणीकरण के शोषण योग्य।
User Interaction
कोई नहीं — स्वचालित और मूक हमला। पीड़ित कुछ नहीं करता।
Scope
अपरिवर्तित — प्रभाव केवल कमज़ोर घटक तक सीमित।
Confidentiality
उच्च — पूर्ण गोपनीयता हानि। हमलावर सभी डेटा पढ़ सकता है।
Integrity
उच्च — हमलावर कोई भी डेटा लिख, बदल या हटा सकता है।
Availability
उच्च — पूर्ण क्रैश या संसाधन समाप्ति। पूर्ण सेवा से इनकार।

प्रभावित सॉफ्टवेयर

घटकmilesight-ms-cxx63-pd
विक्रेताMilesight
न्यूनतम संस्करण0.0.0
अधिकतम संस्करणT_63.8.0.4_LPR-r3

कमजोरी वर्गीकरण (CWE)

समयरेखा

  1. प्रकाशित
  2. संशोधित
  3. EPSS अद्यतन

शमन और वर्कअराउंडअनुवाद हो रहा है…

The primary mitigation for CVE-2026-27785 is to upgrade the Milesight MS-Cxx63-PD AIOT Camera Firmware to a version that addresses the hardcoded credentials issue. Unfortunately, a fixed version is not yet specified. Until a patch is available, consider isolating the camera from the network to prevent unauthorized access. Implement strict network segmentation to limit the potential impact of a compromise. Monitor network traffic for unusual activity originating from the camera's IP address. Review and strengthen password policies for all other network devices to prevent lateral movement. After upgrade, confirm by attempting to access the camera's configuration interface with known, strong credentials.

कैसे ठीक करेंअनुवाद हो रहा है…

Actualice el firmware de la cámara Milesight MS-Cxx63-PD a una versión corregida que no contenga las credenciales codificadas. Consulte la página de soporte de Milesight para obtener las últimas versiones de firmware y las instrucciones de actualización.

अक्सर पूछे जाने वाले सवालअनुवाद हो रहा है…

What is CVE-2026-27785 — Hardcoded Credentials in Milesight AIOT Camera?

CVE-2026-27785 is a HIGH severity vulnerability affecting Milesight MS-Cxx63-PD AIOT Camera Firmware versions 0.0.0–T63.8.0.4LPR-r3. It involves hardcoded credentials, allowing unauthorized access to the camera and its data.

Am I affected by CVE-2026-27785 in Milesight AIOT Camera?

If you are using Milesight MS-Cxx63-PD AIOT Camera Firmware versions between 0.0.0 and T63.8.0.4LPR-r3, you are potentially affected by this vulnerability. Check your firmware version immediately.

How do I fix CVE-2026-27785 in Milesight AIOT Camera?

The recommended fix is to upgrade to a patched firmware version. Unfortunately, a fixed version is not yet specified. Until a patch is available, isolate the camera from the network.

Is CVE-2026-27785 being actively exploited?

There is currently no indication that CVE-2026-27785 is being actively exploited in the wild, but the nature of hardcoded credentials makes exploitation likely.

Where can I find the official Milesight advisory for CVE-2026-27785?

Refer to the Milesight website and security advisories for updates and information regarding CVE-2026-27785. Monitor CISA and NVD for updates as well.

क्या आपका प्रोजेक्ट प्रभावित है?

अपनी डिपेंडेंसी फ़ाइल अपलोड करें और तुरंत जानें कि यह CVE और अन्य आपको प्रभावित करती हैं या नहीं।

liveमुफ्त स्कैन

अभी आज़माएँ — no खाता

scanZone.subtitle

मैनुअल स्कैनSlack/email अलर्टContinuous monitoringscanZone.capReports

अपनी डिपेंडेंसी फ़ाइल ड्रैग और ड्रॉप करें

composer.lock, package-lock.json, requirements.txt, Gemfile.lock, pubspec.lock, Dockerfile...