CVE-2026-40623
Last modified
CVE-2026-40623 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog timers, reconnect intervals, and service ports can be set to unsupported or unsafe values. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A vulnerability in SenseLive X3050's web management interface allows critical system and network configuration parameters to be modified without sufficient validation and safety controls. Due to inadequate enforcement of constraints on sensitive functions, parameters such as IP addressing, watchdog timers, reconnect intervals, and service ports can be set to unsupported or unsafe values. These configuration changes directly affect core device behaviour and recovery mechanisms. The lack of proper validation and safeguards allows critical system functions to be altered in a manner that can destabilize device operation or render the device persistently unavailable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Senselive | X3500 Firmware | 1.523 |
References
- https://senselive.io/contactProduct
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-12US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-40623?
How severe is CVE-2026-40623?
How do I fix CVE-2026-40623?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-40618When an SSL profile is configured on a virtual server on BIG…8.7
- CVE-2026-40619A high security vulnerability affecting Security Center main…7.8
- CVE-2026-4062The Geo Mashup plugin for WordPress is vulnerable to Time-Ba…7.5
- CVE-2026-40620A vulnerability in SenseLive X3050’s embedded management ser…9.8
- CVE-2026-40621ELECOM wireless LAN access point devices do not require auth…9.8
- CVE-2026-40622NLnet Labs Unbound 1.16.2 up to and including version 1.25.0…7.5
- CVE-2026-40624Improper input validation in AVer PTC500S, PTC115, PTC500+, …9.8
- CVE-2026-40629When SSL profiles are configured on a virtual server, undisc…8.7
- CVE-2026-4063The Social Icons Widget & Block by WPZOOM plugin for WordPre…4.3
- CVE-2026-40630A vulnerability in SenseLive X3050’s web management inter…9.8
- CVE-2026-40631An authenticated attacker with the Resource Administrator or…8.7
- CVE-2026-40633Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, ver…5.5
Are you affected by CVE-2026-40623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
