Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilityembedded-device-vulnerabilityinternet-facing-service-vulnerabilityoperational-disruption

SenseLive X3050 Flaws Allow Unauthenticated Admin Access and Persistent Device Lockout

Updated 2mo agoFirst seen Apr 24, 20264 sources

Multiple high-severity vulnerabilities in the SenseLive X3050 industrial gateway expose its web and embedded management interfaces to unauthenticated or improperly authorized remote access. The issues tracked as CVE-2026-40620, CVE-2026-40630, CVE-2026-40623, and CVE-2026-27843 include missing authentication for critical functions, authentication bypass via an alternate path or channel, and missing authorization. Collectively, the flaws allow attackers with network reachability to access sensitive configuration endpoints, gain administrative control of the configuration application, and change operational modes, service ports, watchdog timers, reconnect intervals, IP settings, and other critical parameters.

The reported impact spans confidentiality, integrity, and availability, with CVSS scoring indicating network-exploitable, low-complexity attacks and high-severity outcomes. Successful exploitation can destabilize the gateway, cause persistent denial of service, and in the case of CVE-2026-27843, lock the device into a state that also disrupts connected RS-485 downstream systems. Recovery may be especially difficult because the X3050 reportedly lacks a physical reset button, requiring specialized console access for a factory reset after destructive configuration changes.

Share:
SenseLive X3050 Flaws Allow Unauthenticated Admin Access and Persistent Device Lockout
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 24, 20262mo ago

CVE-2026-40630 assigned for SenseLive X3050 auth bypass

CVE-2026-40630 was assigned to an authentication bypass vulnerability in the SenseLive X3050 web management interface that allows network-accessible attackers to reach sensitive configuration endpoints without authorization.

CVE-2026-27843 assigned for lockout-causing config flaw

CVE-2026-27843 was assigned to a missing-authentication flaw in the SenseLive X3050 web management interface that lets an unauthenticated attacker set disruptive values, potentially causing persistent lockout and denial of service requiring console-based factory reset.

CVE-2026-40623 assigned for unsafe configuration changes

CVE-2026-40623 was assigned to a missing-authorization issue in the SenseLive X3050 web management interface that permits modification of critical system and network settings, potentially destabilizing the device or making it unavailable.

CVE-2026-40620 assigned for unauthenticated admin access

CVE-2026-40620 was assigned to a missing-authentication flaw in the SenseLive X3050 embedded management service that allows a remote unauthenticated attacker to gain full administrative control over the configuration application.

ICS-CERT receives four SenseLive X3050 vulnerability reports

On April 24, 2026, ICS-CERT/CISA received multiple vulnerability reports affecting the SenseLive X3050, including authentication bypass, missing authentication, and missing authorization flaws in its web and embedded management interfaces.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Affected products
1 linked
X3050
Organizations
1 linked
SenseLive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.