


Perceptive Security
SOC/SIEM Consultancy

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded valu…
Published:
23 april 2026 om 22:00:00
Alert date:
24 april 2026 om 17:03:09
Source:
nvd.nist.gov
Mobile & IoT, Identity & Access, Web Technologies
A critical vulnerability in SenseLive X3050's web management interface allows complete authentication bypass through client-side logic manipulation. The authentication mechanism relies entirely on hardcoded values within browser-executed scripts rather than proper server-side verification. Attackers can access the login page and retrieve exposed authentication parameters to gain unauthorized administrative access. This represents a fundamental security design flaw that completely undermines the authentication system. The vulnerability affects the web management interface of SenseLive X3050 devices and could allow full administrative compromise.
Technical details
Mitigation steps:
Affected products:
SenseLive X3050
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-35503
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-111-12.json
https://senselive.io/contact
https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
