CVE-2026-25720: Senselive x3500 Firmware
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased.
Affected products
- Senselive x3500 Firmware: version 1.523 only
Published 2026-04-24. Last modified 2026-06-17.