9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.
AI Analysis
Unauthenticated access to administrative control of SenseLive X3050 devices
Basic Information
ID
CVE-2026-40620
Source
icscert
Published
Apr 24, 2026 at 00:02
Affected Product
Vendor
SenseLive
Product
X3050
Version
V1.523
Affected Versions
SenseLive X3050 V1.523
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
SenseLive
Product
SenseLive X3050
Version
V1.523