# CVE-2026-39462

> Vulnerability · severity: **HIGH** (CVSS 8.1).

## Description

A vulnerability exists in SenseLive X3050’s web management interface in which password updates are not reliably applied due to improper handling of credential changes on the backend. After the device undergoes a factory restore using the SenseLive Config 2.0 tool, the interface may indicate that the password update was successful; however, the system may continue to accept the previous or default credentials, demonstrating that the password-change process is not consistently enforced. Even after a factory reset, attempted password changes may fail to propagate correctly.

## Key facts

- **CVE ID:** CVE-2026-39462
- **Published:** 2026-04-24
- **CVSS severity:** HIGH
- **CVSS base score:** 8.1
- **CWE codes:** CWE-522

## Affected products

- `senselive:x3500_firmware`
- `senselive:x3500`

## Primary sources

- NIST NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-39462

## Citation

> AI Analytics. CVE-2026-39462. Retrieved 2026-07-23 from https://api.ai-analytics.org/cve/CVE-2026-39462. Derived from NIST NVD. Licensed CC0.

---

*[Dataset catalog](https://api.ai-analytics.org/datasets/) · [AI Analytics](https://api.ai-analytics.org/) · CC0 1.0*