Home

Description

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.

PUBLISHED Reserved 2026-04-14 | Published 2026-04-24 | Updated 2026-04-24 | Assigner icscert




CRITICAL: 9.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-306 Missing authentication for critical function

Product status

Default status
unaffected

V1.523
affected

Credits

Jithin Nambiar J reported these vulnerabilities to CISA. finder

References

senselive.io/contact

www.cisa.gov/news-events/ics-advisories/icsa-26-111-12

github.com/...p/csaf_files/OT/white/2026/icsa-26-111-12.json

cve.org (CVE-2026-40620)

nvd.nist.gov (CVE-2026-40620)

Download JSON