Impact
A flaw in the SenseLive X3050 web management interface causes password changes to be inconsistently applied. After updating the password, the interface may report success while the system still accepts the old or default credentials, allowing an authenticated user to maintain or acquire privileged access. The weakness can lead to unauthorized control of the device and the data it handles.
Affected Systems
SenseLive X3050 devices, all firmware versions for which no specific affected-version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 9.3 marks this as a high severity vulnerability, while the EPSS score of less than 1% indicates a low likelihood of current exploitation. It is not listed in CISA’s KEV catalog. The vulnerability is exploitable via the device’s web interface, which is typically reachable over a network; an attacker who has or can guess valid credentials can benefit from the ineffective password change process. No additional conditions are required beyond the ability to log in or reset the device using the vendor’s Config 2.0 tool.
OpenCVE Enrichment