CVE-2026-40620 PUBLISHED

SenseLive X3050 Missing authentication for critical function

Assigner: icscert
Reserved: 14.04.2026 Published: 24.04.2026 Updated: 24.04.2026

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor SenseLive
Product X3050
Versions Default: unaffected
  • Version V1.523 is affected

Solutions

SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact

Credits

  • Jithin Nambiar J reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE