MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
The vulnerability lies in the way cryptographic keys are managed in the Milesight DeviceHub application. Improper implementation or storage of keys may allow an attacker to bypass authentication mechanisms, as well as intercept and potentially modify network traffic in a Man-In-The-Middle attack. The attack does not require user interaction or prior system privileges.
An attacker can gain unauthorized access to the system by bypassing authentication, and can intercept or modify transmitted data, leading to serious breach of confidentiality and integrity.
Apply patches available from the manufacturer in accordance with the references provided
Milesight DeviceHub — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NCanonical Ubuntu
OSCanonical20.04Milesight Devicehub
APPMilesight3.0.1-r1
Related vulnerabilities
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
Redis – ucieczka z Lua sandbox umożliwiająca zdalne wykonanie kodu (RCE)
SaltStack Salt: nieautoryzowany dostęp do metod salt-master umożliwiający RCE
RCE jako root w OpenSMTPD przez command injection w polu MAIL FROM
RCE w Exim — heap-based buffer overflow w obsłudze komendy EHLO