TopVuln

High-risk vulnerability digests

CVE-2026-40620

  • CRITICAL

ics-cert@hq.dhs.gov

Details

CVSS v3
9.8
CVSS v4
9.3
NVD published
2026-04-24 00:16:28
EPSS
<0.1% probability · 22.6th percentile — 2026-05-12
Affected versions
SenseLive X3050 embedded management devices
Summary
This vulnerability affects the embedded management service of SenseLive X3050 devices. It allows attackers to gain full administrative control without any authentication or authorization checks. Any reachable host can connect to the service and modify critical device configurations, operational modes, and core device state.
Remediation
Apply the latest official security patch from SenseLive if it is available. If no patch is released, restrict management service access to only trusted internal networks. Monitor for unauthorized configuration changes to detect potential compromise.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.