Executive brief
The SenseLive X3050, an industrial IoT gateway used in sectors like energy and manufacturing, contains a critical security flaw in its remote management service. This flaw allows unauthorized individuals to download the device's internal software (firmware) or upload malicious updates without needing a password. An attacker could use this to take full control of the device, disrupt operations, or gain access to sensitive industrial data.
Technical details
A critical vulnerability (CWE-306) exists in the remote management service of the SenseLive X3050 industrial gateway. The service fails to implement authentication or authorization checks for firmware-related requests, accepting them from any network-reachable host. Furthermore, the device does not verify the integrity of uploaded images or the authenticity of the firmware provider. An unauthenticated remote attacker can exploit this to retrieve the current firmware or upload a malicious firmware image, leading to a complete compromise of the device. As of the advisory date, the vendor has not responded to coordination efforts, and no official patch is available.
Affected products
- SenseLive X3050 V1.523
Timeline
- 2026-04-21: advisory: CISA ICSA-26-111-12 published
- 2026-04-24: disclosed: NVD publication date