X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased.
No analysis available yet.
Vendor Solution
SenseLive did not respond to CISA's requests to coordinate. Affected users are encouraged to reach out to SenseLive for more information. https://senselive.io/contact
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased. | |
| Title | SenseLive X3050 Insufficient session expiration | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2026-04-23T23:48:16.663Z
Reserved: 2026-04-14T16:05:54.140Z
Link: CVE-2026-25720
No data.
Status : Received
Published: 2026-04-24T00:16:26.577
Modified: 2026-04-24T00:16:26.577
Link: CVE-2026-25720
No data.
OpenCVE Enrichment
No data.