← Vulnerability feed

Vulnerability record · CVE-2026-35064 · published 24 April 2026

CVE-2026-35064: Senselive x3500 firmware missing authentication for critical function vulnerability

Senselive · X3500 Firmware

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exposed by the underlying service rather than gated by authentication, an attacker on the same network segment can rapidly enumerate targeted devices.

8.7 CVSS 4.0 High EPSS 0.63% · top 51.7% CWE-306 · Missing authentication for critical function
8.7CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A vulnerability in SenseLive X3050’s management ecosystem allows unauthenticated discovery of deployed units through the vendor’s management protocol, enabling identification of device presence, identifiers, and management interfaces without requiring credentials. Because discovery functions are exposed by the underlying service rather than gated by authentication, an attacker on the same network segment can rapidly enumerate targeted devices.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-35064 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-40630Senselive x3500 firmware authentication bypass via alternate path vulnerabilityA vulnerability in  SenseLive X3050’s web management interface allows unauthorized access to certain configuration endpoints due to improper access c…EPSS 0.89%9.3CVE-2026-35503Senselive x3500 firmware hard-coded credentials vulnerabilityA vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on har…EPSS 0.84%9.3CVE-2026-39462Senselive x3500 firmware insufficiently protected credentials vulnerabilityA vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of c…EPSS 0.69%9.3CVE-2026-40620Senselive x3500 firmware missing authentication for critical function vulnerabilityA vulnerability in SenseLive X3050’s embedded management service allows full administrative control to be established without any form of authenticat…EPSS 0.83%9.2CVE-2026-27843Senselive x3500 firmware missing authentication for critical function vulnerabilityA vulnerability exists in SenseLive X3050's web management interface that allows critical configuration parameters to be modified without sufficient …EPSS 0.81%8.4CVE-2026-27841Senselive x3500 firmware cross-site request forgery vulnerabilityA vulnerability in SenseLive X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forg…EPSS 0.25%7.2CVE-2026-40623Senselive x3500 firmware missing authorization vulnerabilityA vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without suff…EPSS 0.59%6.9CVE-2026-40431Senselive x3500 firmware cleartext transmission vulnerabilityA vulnerability exists in SenseLive X3050’s web management interface due to its reliance on unencrypted HTTP for all administrative communication. Be…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2026-35064), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.