CVE-2026-40431 PUBLISHED

SenseLive X3050 Cleartext transmission of sensitive information

Assigner: icscert
Reserved: 14.04.2026 Published: 23.04.2026 Updated: 23.04.2026

A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is transmitted in cleartext, an attacker with access to the same network segment could intercept or observe sensitive operational information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor SenseLive
Product X3050
Versions Default: unaffected
  • Version V1.523 is affected

Solutions

SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact

Credits

  • Jithin Nambiar J reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-319 Cleartext transmission of sensitive information CWE