PT-2026-35570 · Milesight · Milesight Cameras

Souvik Kandar

·

Published

2026-04-27

·

Updated

2026-04-28

·

CVE-2026-32649

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Milesight cameras (affected versions not specified)
Description A command injection flaw exists in the web server of the camera firmware. Command injection is a type of attack where an attacker can execute arbitrary operating system commands on the server by exploiting an application that improperly validates input.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32649

Affected Products

Milesight Cameras