CVE-2026-35503

Severity CVSS v4.0:
CRITICAL
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
24/04/2026
Last modified:
28/04/2026

Description

A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these exposed parameters and gain unauthorized access to administrative functionality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:senselive:x3500_firmware:1.523:*:*:*:*:*:*:*
cpe:2.3:h:senselive:x3500:-:*:*:*:*:*:*:*