Loading market data...
← Back to CVE feed

CVE-2026-40620

CRITICAL CVSS 9.8 View on NVD ↗

Description

A vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authentication or authorization on the SenseLive config application. The service accepts management connections from any reachable host, enabling unrestricted modification of critical configuration parameters, operational modes, and device state through a vendor-supplied or compatible client.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published: Apr 24, 2026 00:16 UTC Modified: Apr 24, 2026 14:40 UTC