


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) …
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 17:03:09
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
A Cross-Site Request Forgery (CSRF) vulnerability affects SenseLive X3050's web management interface. The vulnerability allows state-changing operations to be triggered without proper CSRF protections. The application lacks server-side validation of request origin and does not implement CSRF tokens. Malicious external webpages can cause unauthorized configuration requests to be submitted through a user's browser. This could lead to unauthorized device configuration changes.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27841
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
