


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded valu…
Published:
23 April 2026 at 22:00:00
Alert date:
24 April 2026 at 01:03:27
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access, Critical Infrastructure
A critical vulnerability in SenseLive X3050's web management interface allows complete bypass of authentication through client-side logic manipulation. The authentication mechanism relies entirely on hardcoded values in browser-executed scripts instead of proper server-side verification. Attackers with access to the login page can extract these exposed parameters from the client-side code to gain unauthorized administrative access. This represents a fundamental security flaw in the authentication architecture that could lead to complete system compromise.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35503
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
