PT-2026-34802 · Unknown · Senselive X3050

Published

2026-04-23

·

Updated

2026-04-25

·

CVE-2026-27843

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions SenseLive X3050 (affected versions not specified)
Description The web management interface allows critical configuration parameters to be modified due to insufficient authentication and a lack of server-side validation. An attacker can apply unsupported or disruptive values to network settings and recovery mechanisms, inducing a persistent lockout state. Since the device lacks a physical reset button, a factory reset requires specialized technical access via the console, leading to a total denial-of-service for the gateway and its connected RS-485 downstream systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-27843

Affected Products

Senselive X3050