Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Senselive x3500
Senselive x3500 Firmware |
|
| CPEs | cpe:2.3:h:senselive:x3500:-:*:*:*:*:*:*:* cpe:2.3:o:senselive:x3500_firmware:1.523:*:*:*:*:*:*:* |
|
| Vendors & Products |
Senselive x3500
Senselive x3500 Firmware |
Tue, 28 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Senselive
Senselive x3050 |
|
| Vendors & Products |
Senselive
Senselive x3050 |
Fri, 24 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these exposed parameters and gain unauthorized access to administrative functionality. | |
| Title | SenseLive X3050 Use of Hard-coded Credentials | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-24T13:51:40.131Z
Reserved: 2026-04-14T16:05:54.153Z
Link: CVE-2026-35503
Updated: 2026-04-24T13:51:36.824Z
Status : Analyzed
Published: 2026-04-24T00:16:28.143
Modified: 2026-04-28T19:33:20.857
Link: CVE-2026-35503
No data.
OpenCVE Enrichment
Updated: 2026-04-28T14:45:16Z