CVE-2016-2359: Milesight IP Security Camera Firmware

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.

Affected products

  • Milesight IP Security Camera Firmware: up to and including 2016-11-14

Published 2019-10-25. Last modified 2026-06-17.