Password Management Flaw in SenseLive X3050 by SenseLive
CVE-2026-39462

9.3CRITICAL

Key Information:

Vendor

Senselive

Status
Vendor
CVE Published:
23 April 2026

What is CVE-2026-39462?

A significant flaw in the web management interface of the SenseLive X3050 affects how password updates are managed. When users attempt to change passwords, particularly after performing a factory restore using the SenseLive Config 2.0 tool, the updates may not be applied correctly. Instead of enforcing the new credentials, the system may continue accepting previous or default passwords. This means that even though the interface indicates a successful password change, the changes do not propagate consistently, potentially leaving the device open to unauthorized access.

Affected Version(s)

X3050 V1.523

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jithin Nambiar J reported these vulnerabilities to CISA.
.