CVE-2026-25775Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization. The service accepts firmware-related requests from any reachable host and does not verify user privileges, integrity of uploaded images, or the authenticity of provided firmware.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-25); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-25: 2Mentions · 2026-04-27: 1Technical Details · 2026-04-25: 2Technical Details · 2026-04-27: 104-2504-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-252
Disclosure2
2026-04-271
Disclosure1
Full discourse3 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-25775 (SenseLive X3050) is a critical missing-authentication vulnerability in remote firmware management. Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-04-24/TIER_2_CVE-2026-25775.md #CyberSecurity #CVE #DPI #IndustrialIoT #OTSecurity

    Post summary

    CVE‑2026‑25775 is disclosed as a critical missing‑authentication flaw affecting remote firmware management on the SenseLive X3050, with a technical analysis available on GitHub.

    0001197
    45 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-25775 A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization… https://www.cve.org/CVERecord?id=CVE-2026-25775 ----- Traducción: CVE-2026-25775 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑25775 and notes that an unauthenticated remote service can retrieve and update firmware, but provides no PoC, exploit code, or patch info.

    0000030
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25775 A vulnerability in SenseLive X3050’s remote management service allows firmware retrieval and update operations to be performed without authentication or authorization… https://www.cve.org/CVERecord?id=CVE-2026-25775

    Post summary

    The post announces a new vulnerability (CVE‑2026‑25775) in SenseLive X3050’s remote management service that permits unauthenticated firmware access, without providing PoC, exploit, or mitigation details.

    00000112
    57.2K followersView on X

Explore more