CVE-2026-40630 PUBLISHED

SenseLive X3050 Authentication bypass using an alternate path or channel

Assigner: icscert
Reserved: 14.04.2026 Published: 23.04.2026 Updated: 23.04.2026

A vulnerability in  SenseLive

X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may be able to bypass the intended authentication mechanism and directly interact with sensitive configuration functions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor SenseLive
Product X3050
Versions Default: unaffected
  • Version V1.523 is affected

Solutions

SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact

Credits

  • Jithin Nambiar J reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-288 Authentication bypass using an alternate path or channel CWE