A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.
References
Configurations
No configuration.
History
24 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-24 00:16
Updated : 2026-04-24 14:39
NVD link : CVE-2026-25775
Mitre link : CVE-2026-25775
CVE.ORG link : CVE-2026-25775
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
