Improper Session Management in SenseLive X3050 Web Management Interface
CVE-2026-25720
6.9MEDIUM
What is CVE-2026-25720?
A significant vulnerability in the web management interface of the SenseLive X3050 arises from improper session lifetime enforcement. This flaw allows authenticated sessions to persist for extended durations without necessitating re-authentication. Consequently, if an attacker gains access to a previously authenticated session, they can interact with sensitive administrative functions, potentially compromising security measures and leading to unauthorized access to critical system controls.
Affected Version(s)
X3050 V1.523
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar J reported these vulnerabilities to CISA.
