Authentication Bypass in SenseLive X3050 Web Management Interface
CVE-2026-35503

9.3CRITICAL

Key Information:

Vendor

Senselive

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-35503?

A flaw in the web management interface of SenseLive X3050 compromises its authentication mechanism by conducting logic checks on the client side. This vulnerable design relies on hardcoded values within browser-executed scripts, neglecting critical server-side validation. As a result, any attacker with access to the login page may exploit this weakness to extract sensitive parameters, potentially gaining unauthorized administrative access and compromising the system's integrity.

Affected Version(s)

X3050 V1.523

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jithin Nambiar J reported these vulnerabilities to CISA.
.