CVE-2026-27785: Hardcoded Credentials in Milesight AIOT Camera
平台
linux
组件
milesight-ms-cxx63-pd
CVE-2026-27785 identifies a critical security flaw within Milesight MS-Cxx63-PD AIOT Camera Firmware. This vulnerability stems from the presence of hardcoded credentials, granting attackers potentially unrestricted access to the camera and its associated data. The affected firmware versions include those from 0.0.0 through T63.8.0.4LPR-r3. A firmware update is necessary to resolve this issue.
影响与攻击场景翻译中…
The presence of hardcoded credentials within the Milesight AIOT camera firmware presents a severe security risk. An attacker who discovers these credentials can gain complete control over the camera, including access to live video feeds, recorded footage, and configuration settings. This could lead to unauthorized surveillance, data theft, and potential manipulation of the camera's functionality. Furthermore, compromised cameras can be leveraged as entry points for lateral movement within a network, potentially impacting other connected devices and systems. The blast radius extends to any sensitive data or systems accessible through the camera.
利用背景翻译中…
CVE-2026-27785 was published on 2026-04-27. The vulnerability's severity is rated HIGH (CVSS: 8.8). There is currently no indication of this vulnerability being actively exploited in the wild. Public proof-of-concept (POC) code is not yet available, but the nature of hardcoded credentials makes it likely that exploits will emerge. Monitor CISA and NVD advisories for updates.
威胁情报
漏洞利用状态
EPSS
0.02% (5% 百分位)
CVSS 向量
这些指标意味着什么?
- Attack Vector
- 相邻 — 需要网络邻近:相同LAN、蓝牙或本地无线网段。
- Attack Complexity
- 低 — 无需特殊条件,可以稳定地利用漏洞。
- Privileges Required
- 无 — 无需认证,无需凭证即可利用。
- User Interaction
- 无 — 攻击自动且无声,受害者无需任何操作。
- Scope
- 未改变 — 影响仅限于脆弱组件本身。
- Confidentiality
- 高 — 完全丧失机密性,攻击者可读取所有数据。
- Integrity
- 高 — 攻击者可写入、修改或删除任何数据。
- Availability
- 高 — 完全崩溃或资源耗尽,完全拒绝服务。
受影响的软件
弱点分类 (CWE)
时间线
- 发布日期
- 修改日期
- EPSS 更新日期
缓解措施和替代方案翻译中…
The primary mitigation for CVE-2026-27785 is to upgrade the Milesight MS-Cxx63-PD AIOT Camera Firmware to a version that addresses the hardcoded credentials issue. Unfortunately, a fixed version is not yet specified. Until a patch is available, consider isolating the camera from the network to prevent unauthorized access. Implement strict network segmentation to limit the potential impact of a compromise. Monitor network traffic for unusual activity originating from the camera's IP address. Review and strengthen password policies for all other network devices to prevent lateral movement. After upgrade, confirm by attempting to access the camera's configuration interface with known, strong credentials.
修复方法翻译中…
Actualice el firmware de la cámara Milesight MS-Cxx63-PD a una versión corregida que no contenga las credenciales codificadas. Consulte la página de soporte de Milesight para obtener las últimas versiones de firmware y las instrucciones de actualización.
常见问题翻译中…
What is CVE-2026-27785 — Hardcoded Credentials in Milesight AIOT Camera?
CVE-2026-27785 is a HIGH severity vulnerability affecting Milesight MS-Cxx63-PD AIOT Camera Firmware versions 0.0.0–T63.8.0.4LPR-r3. It involves hardcoded credentials, allowing unauthorized access to the camera and its data.
Am I affected by CVE-2026-27785 in Milesight AIOT Camera?
If you are using Milesight MS-Cxx63-PD AIOT Camera Firmware versions between 0.0.0 and T63.8.0.4LPR-r3, you are potentially affected by this vulnerability. Check your firmware version immediately.
How do I fix CVE-2026-27785 in Milesight AIOT Camera?
The recommended fix is to upgrade to a patched firmware version. Unfortunately, a fixed version is not yet specified. Until a patch is available, isolate the camera from the network.
Is CVE-2026-27785 being actively exploited?
There is currently no indication that CVE-2026-27785 is being actively exploited in the wild, but the nature of hardcoded credentials makes exploitation likely.
Where can I find the official Milesight advisory for CVE-2026-27785?
Refer to the Milesight website and security advisories for updates and information regarding CVE-2026-27785. Monitor CISA and NVD for updates as well.
立即试用 — 无需账户
上传任何清单文件 (composer.lock, package-lock.json, WordPress 插件列表…) 或粘贴您的组件列表。您立即获得一份漏洞报告。上传文件只是开始:拥有账户后,您将获得持续监控、Slack/电子邮件警报、多项目和白标报告。
拖放您的依赖文件
composer.lock、package-lock.json、requirements.txt、Gemfile.lock、pubspec.lock、Dockerfile...