PT-2026-34802 · Unknown · Senselive X3050
Published
2026-04-23
·
Updated
2026-04-25
·
CVE-2026-27843
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SenseLive X3050 (affected versions not specified)
Description
The web management interface allows critical configuration parameters to be modified due to insufficient authentication and a lack of server-side validation. An attacker can apply unsupported or disruptive values to network settings and recovery mechanisms, inducing a persistent lockout state. Since the device lacks a physical reset button, a factory reset requires specialized technical access via the console, leading to a total denial-of-service for the gateway and its connected RS-485 downstream systems.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Senselive X3050