CVE-2026-25720 PUBLISHED

SenseLive X3050 Insufficient session expiration

Assigner: icscert
Reserved: 14.04.2026 Published: 23.04.2026 Updated: 23.04.2026

A vulnerability exists in SenseLive

X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor SenseLive
Product X3050
Versions Default: unaffected
  • Version V1.523 is affected

Solutions

SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact

Credits

  • Jithin Nambiar J reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-613 Insufficient session expiration CWE