CVE Intelligence
Skip to main content
CRITICAL

CVE-2026-32644

CVE-2026-32644 — Milesight Cameras Use of Hard-coded Cryptographic Key

Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

Published Updated Sources: cvelistV5, icscert

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

0%

chance of exploitation in 30 days

Affects

milesight

82 products listed

CVSS base

9.8

CRITICAL

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

Yes

can an attacker script all four kill-chain steps

Technical impact

Total

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (82)

ms cxx63 pdms cxx64 xpdms cxx73 xpdms cxx75 xxpdms cxx83 xpdms cxx74 pams c8477 hpg1ms c8477 pcms c5321 fpems cxx72 xxxpems cxx62 xxxpems cxx52 xxxpems cxx66 xxxpems cxx66 xxxgpems cxx61 xxxpems cxx67 xxxpems cxx71 xxxpems cxx41 xxxpems cxx76 pems cxx65 pems cxx66 xxxg1ms cxx62 xxxg1ms cxx72 xxxg1ms cqxx31 xxxg1ms cqxx68 xxxg1ms cqxx72 xxxg1ms nxxxx nxems nxxxx xxcms nxxxx xxems nxxxx xxgms nxxxx xxhms nxxxx xxtpmc8266 fpepmc8266 fgpepm3322 ets4466 x4ripg1ts5366 x12ripg1ts8266 x4ripg1ts4466 x4rivpg1ts4466 rfivpg1ts8266 x4rivpg1ts8266 rfivpg1ts4466 x4riwg1ts8266 x4riwg1ts5510 gvhts5510 ghts5511 gvhts2966 x12tpets4466 x4rpets5366 x12pets8266 x4pets2966 x12tvpets4466 x4rvpets5366 x12vpets8266 x4vpets4441 x36rpets4441 x36rets4466 x4rwets8266 x4wems c2964 rflpcms c2972 rflpcms c2966 rflwpcts2866 x4tpcts2866 x4tvpcts2866 x4tgpcts2841 x36tpcts2841 x36tpc wts2867 x5tpcts2961 x12tpcts8266 fpc pms c2966 x12rlpcms c2966 x12rlvpcms c5366 x12lpcms c5366 x12lvpcms c5361 x12lpcms cxx66 xxxxgopcsc211sp111ms cxx66 rfipkg1ms cxx72 rfipkg1ms cxx66 fipkg1ms cxx72 fipkg1

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
9.8CVSS 3.1CRITICALcvelistV5

Weakness & attack patterns

  • CWE-321

References

3 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.