


Perceptive Security
SOC/SIEM Consultancy

A vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient authenticat…
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 17:03:09
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure
A critical vulnerability in SenseLive X3050's web management interface allows attackers to modify configuration parameters without proper authentication or validation. Attackers can apply disruptive values to recovery mechanisms and network settings, causing a persistent lockout state. The device lacks a physical reset button, requiring specialized console access for factory reset. This results in complete denial-of-service for the gateway and all connected RS-485 downstream systems. Recovery is complex and requires technical expertise to restore functionality.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-27843
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
