SenseLive X3050是日本SenseLive公司的一款面向物联网场景的数据采集与环境监测设备。 SenseLive X3050存在访问控制错误漏洞,该漏洞源于远程管理服务允许未经身份验证或授权执行固件检索和更新操作,服务接受来自任何可达主机的固件相关请求且不验证用户权限、上传镜像完整性或固件真实性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-40620 | 9.8 CRITICAL | SenseLive X3050 Missing authentication for critical function |
| CVE-2026-27841 | 8.1 HIGH | SenseLive X3050 Cross-Site request forgery |
| CVE-2026-35064 | 7.5 HIGH | SenseLive X3050 Missing authentication for critical function |
No comments yet