Configuration Manipulation in SenseLive X3050's Web Management Interface
CVE-2026-27843
9.2CRITICAL
What is CVE-2026-27843?
A vulnerability exists in the web management interface of the SenseLive X3050, allowing unauthorized modifications to critical configuration parameters. This lack of sufficient authentication or server-side validation enables attackers to input unsupported or malicious values into recovery mechanisms and network settings. Consequently, this can lead to a persistent lockout state of the device. As the X3050 does not possess a physical reset button, recovering from this state necessitates specialized technical access, performed via console to execute a factory reset. This results in a denial-of-service for both the gateway and connected RS-485 downstream systems.
Affected Version(s)
X3050 V1.523
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jithin Nambiar J reported these vulnerabilities to CISA.
