


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) …
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 01:03:27
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Critical Infrastructure
A Cross-Site Request Forgery (CSRF) vulnerability in SenseLive X3050's web management interface allows unauthorized state-changing operations. The application lacks proper CSRF protections including server-side validation of request origin and CSRF tokens. This vulnerability enables malicious external webpages to cause a user's browser to submit unauthorized configuration requests to the device. The flaw affects the web management interface specifically and could lead to unauthorized device configuration changes. This is classified as a high-severity vulnerability affecting IoT device management systems.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27841
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
