Metrics
Affected Vendors & Products
No advisories yet.
Solution
SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact
Workaround
No workaround given by the vendor.
Fri, 24 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog timers, reconnect intervals, and service ports can be set to unsupported or unsafe values. These configuration changes directly affect core device behaviour and recovery mechanisms. The lack of proper validation and safeguards allows critical system functions to be altered in a manner that can destabilize device operation or render the device persistently unavailable. | |
| Title | SenseLive X3050 Missing Authorization | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-23T23:58:47.343Z
Reserved: 2026-04-14T15:57:14.970Z
Link: CVE-2026-40623
No data.
Status : Awaiting Analysis
Published: 2026-04-24T00:16:28.860
Modified: 2026-04-24T14:40:12.517
Link: CVE-2026-40623
No data.
OpenCVE Enrichment
No data.