Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Senselive x3500
Senselive x3500 Firmware |
|
| CPEs | cpe:2.3:h:senselive:x3500:-:*:*:*:*:*:*:* cpe:2.3:o:senselive:x3500_firmware:1.523:*:*:*:*:*:*:* |
|
| Vendors & Products |
Senselive x3500
Senselive x3500 Firmware |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Senselive
Senselive x3050 |
|
| Vendors & Products |
Senselive
Senselive x3050 |
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or disruptive values to recovery mechanisms and network settings, an attacker can induce a persistent lockout state. Because the device lacks a physical reset button, recovery requires specialized technical access via the console to perform a factory reset, resulting in a total denial-of-service for the gateway and its connected RS-485 downstream systems. | |
| Title | SenseLive X3050 Missing authentication for critical function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-24T13:10:40.862Z
Reserved: 2026-04-14T16:05:54.167Z
Link: CVE-2026-27843
Updated: 2026-04-24T13:10:36.600Z
Status : Analyzed
Published: 2026-04-24T00:16:27.123
Modified: 2026-04-28T19:32:43.943
Link: CVE-2026-27843
No data.
OpenCVE Enrichment
Updated: 2026-04-28T20:30:06Z