9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.
AI Analysis
Missing authentication for critical function in SenseLive X3050’s remote management service
Basic Information
ID
CVE-2026-25775
Source
icscert
Published
Apr 24, 2026 at 00:06
Affected Product
Vendor
SenseLive
Product
X3050
Version
V1.523
Affected Versions
SenseLive X3050 V1.523
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
SenseLive
Product
X3050
Version
V1.523