Senselive
Senselive X3500 Firmware: vulnerabilidades y CVE
Senselive X3500 Firmware tiene 10 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses10
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-40630 | Crítica (9.3) | 0.89% | — | 24 abr 2026 | A vulnerability in SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access control enforcement. An attacker with network access to the device may… |
| CVE-2026-40623 | Alta (7.2) | 0.59% | — | 24 abr 2026 | A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement… |
| CVE-2026-40620 | Crítica (9.3) | 0.83% | — | 24 abr 2026 | A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service… |
| CVE-2026-40431 | Media (6.9) | 0.31% | — | 24 abr 2026 | A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and… |
| CVE-2026-39462 | Crítica (9.3) | 0.69% | — | 24 abr 2026 | A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory… |
| CVE-2026-35503 | Crítica (9.3) | 0.84% | — | 24 abr 2026 | A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side… |
| CVE-2026-35064 | Alta (8.7) | 0.63% | — | 24 abr 2026 | A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and… |
| CVE-2026-27843 | Crítica (9.2) | 0.81% | — | 24 abr 2026 | A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authentication or server-side validation. By applying unsupported or… |
| CVE-2026-27841 | Alta (8.4) | 0.25% | — | 24 abr 2026 | A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce… |
| CVE-2026-25720 | Media (6.9) | 0.40% | — | 24 abr 2026 | A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.