


Perceptive Security
SOC/SIEM Consultancy

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authenticat…
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 15:07:56
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
A critical vulnerability in SenseLive X3050's web management interface allows unauthorized modification of configuration parameters without proper authentication or validation. Attackers can exploit this flaw to disrupt recovery mechanisms and network settings, causing a persistent lockout state. The device lacks a physical reset button, making recovery extremely difficult and requiring specialized console access for factory reset. This results in complete denial-of-service for the gateway and all connected RS-485 downstream systems, making it a high-impact vulnerability for industrial environments.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27843
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
