CVE-2026-40431
SenseLive X3050 Cleartext transmission of sensitive information
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Because management traffic, including authentication attempts and configuration data, is transmitted in cleartext, an attacker with access to the same network segment could intercept or observe sensitive operational information.
| CWE | CWE-319 |
| Vendor | senselive |
| Product | x3050 |
| Published | Apr 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for senselive x3050
Be the first to know when new medium vulnerabilities affecting senselive x3050 are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
SenseLive / X3050
V1.523
References
Credits
Jithin Nambiar J reported these vulnerabilities to CISA.