Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Senselive
Senselive x3050 |
|
| Vendors & Products |
Senselive
Senselive x3050 |
Fri, 24 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware. | |
| Title | SenseLive X3050 Missing authentication for critical function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-24T12:16:24.207Z
Reserved: 2026-04-14T15:57:15.003Z
Link: CVE-2026-25775
Updated: 2026-04-24T12:16:19.103Z
Status : Awaiting Analysis
Published: 2026-04-24T00:16:26.757
Modified: 2026-04-24T14:39:56.310
Link: CVE-2026-25775
No data.
OpenCVE Enrichment
Updated: 2026-04-28T14:30:33Z