CVE-2026-25720: Senselive x3500 Firmware

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allowing authenticated sessions to remain active for extended periods without requiring re-authentication. An attacker with access to a previously authenticated session could continue interacting with administrative functions long after legitimate user activity has ceased.

Affected products

Published 2026-04-24. Last modified 2026-06-17.