CVE-2026-27841

A vulnerability inĀ SenseLiveĀ X3050's web management interface allows state-changing operations to be triggered without proper Cross-Site Request Forgery (CSRF) protections. Because the application does not enforce server-side validation of request origin or implement CSRF tokens, a malicious external webpage could cause a user's browser to submit unauthorized configuration requests to the device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:senselive:x3500_firmware:1.523:*:*:*:*:*:*:*
cpe:2.3:h:senselive:x3500:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-24 00:16

Updated : 2026-06-17 10:27


NVD link : CVE-2026-27841

Mitre link : CVE-2026-27841

CVE.ORG link : CVE-2026-27841


JSON object : View

Products Affected

senselive

  • x3500_firmware
  • x3500
CWE
CWE-352

Cross-Site Request Forgery (CSRF)