CVE 9.3 CRITICAL

SenseLive X3050 Missing authentication for critical function_CVE-2026-40620

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.

AI Analysis

Unauthenticated access to administrative control of SenseLive X3050 devices

Basic Information

ID CVE-2026-40620
Source icscert
Published Apr 24, 2026 at 00:02

Affected Product

Vendor SenseLive
Product X3050
Version V1.523
Affected Versions SenseLive X3050 V1.523

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor SenseLive
Product SenseLive X3050
Version V1.523

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.