A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-25775

CVE-2026-25775: SenseLive X3050 Auth Bypass Vulnerability

CVE-2026-25775 is an authentication bypass flaw in SenseLive X3050's remote management service that allows unauthorized firmware operations. This article covers the technical details, affected systems, and mitigation.

Updated: May 14, 2026

CVE-2026-25775 Overview

CVE-2026-25775 is a missing authentication vulnerability [CWE-306] in the SenseLive X3050 remote management service. The service accepts firmware retrieval and update requests from any reachable host without verifying user privileges. It also fails to validate the integrity or authenticity of uploaded firmware images. Attackers on the network can read existing firmware or push attacker-controlled images to the device. The flaw affects industrial control systems (ICS) deployments and is tracked under CISA advisory ICSA-26-111-12.

Critical Impact

An unauthenticated network attacker can replace device firmware with a malicious image, achieving full and persistent compromise of the SenseLive X3050.

Affected Products

  • SenseLive X3050 industrial gateway
  • Devices exposing the remote management service to reachable networks
  • Deployments without network-layer access restrictions to management interfaces

Discovery Timeline

  • 2026-04-24 - CVE-2026-25775 published to the National Vulnerability Database (NVD)
  • 2026-04-24 - Last updated in NVD database

Technical Details for CVE-2026-25775

Vulnerability Analysis

The SenseLive X3050 exposes a remote management service that handles firmware operations. The service processes firmware retrieval and update requests without enforcing authentication or authorization. Any host that can reach the management port can issue firmware commands.

The service also omits cryptographic validation of firmware images. It does not verify a digital signature, certificate chain, or hash from a trusted source. As a result, attackers can supply arbitrary firmware payloads that the device accepts and installs as legitimate.

Firmware-level compromise grants persistent control below the operating system. Attackers can implant backdoors, disable security controls, intercept industrial traffic, and pivot into operational technology (OT) networks. The vulnerability is classified under [CWE-306] Missing Authentication for Critical Function.

Root Cause

The root cause is the absence of two security controls on a critical function. First, the remote management service does not require authentication or check privileges before accepting firmware-related requests. Second, the firmware update path does not verify image integrity or origin. Either control alone would mitigate the attack, and both are missing.

Attack Vector

The attack is performed over the network with no privileges and no user interaction. An attacker locates the X3050 management service, retrieves the running firmware to analyze it, then crafts a modified image. The attacker submits the malicious image through the same unauthenticated channel. The device installs the firmware because it does not validate the source or signature.

For technical details, refer to the CISA ICS Advisory ICSA-26-111-12 and the GitHub CSAF JSON Document.

Detection Methods for CVE-2026-25775

Indicators of Compromise

  • Unexpected firmware version strings or build timestamps reported by the X3050 device
  • Outbound connections from the device to unfamiliar IP addresses or domains after a management session
  • Firmware update events in device logs without a corresponding administrator change ticket
  • Network traffic to the X3050 remote management port from hosts outside the OT management subnet

Detection Strategies

  • Capture and baseline the firmware hash of each X3050 unit, then alert on any deviation from the approved value
  • Monitor network flows to the management service and flag firmware retrieval or upload requests from non-administrative sources
  • Inspect device syslog or SNMP traps for firmware update and reboot events that do not align with change windows

Monitoring Recommendations

  • Ingest ICS device logs and network metadata into a centralized analytics platform for correlation across the fleet
  • Track configuration drift on X3050 devices using periodic polling and compare against a known-good inventory
  • Alert on any new listener or service binding originating from the X3050 after a firmware change

How to Mitigate CVE-2026-25775

Immediate Actions Required

  • Restrict network access to the X3050 remote management service so only dedicated jump hosts on the OT management VLAN can reach it
  • Place affected devices behind an industrial firewall and block management ports from general corporate and internet routes
  • Capture and store a verified firmware hash for each device so any unauthorized change can be detected quickly
  • Contact the vendor through SenseLive Contact Information for patch availability and guidance

Patch Information

At the time of NVD publication on 2026-04-24, no fixed firmware version is listed in the CVE record. Refer to the CISA ICS Advisory ICSA-26-111-12 for the latest remediation status and any vendor-issued firmware that adds authentication and signature verification to the management service.

Workarounds

  • Segment the X3050 into a dedicated OT subnet with strict allowlists at the gateway
  • Disable remote management on devices that do not require it and manage them locally
  • Require all administrative access to traverse a jump host with multi-factor authentication (MFA) and session recording
  • Monitor for and physically inspect devices showing unexpected reboots or firmware changes until a vendor fix is applied

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechSenselive

  • SeverityCRITICAL

  • CVSS Score9.3

  • EPSS Probability0.08%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-306
  • Technical References
  • GitHub CSAF JSON Document

  • SenseLive Contact Information

  • CISA ICS Advisory ICSA-26-111-12
  • Related CVEs
  • CVE-2026-35503: Senselive X3500 Auth Bypass Vulnerability

  • CVE-2026-40620: Senselive X3500 Auth Bypass Vulnerability

  • CVE-2026-25720: Senselive X3500 Auth Bypass Vulnerability

  • CVE-2026-39462: SenseLive X3500 Auth Bypass Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English