漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SenseLive X3050 Use of Hard-coded Credentials
Vulnerability Description
A vulnerability in SenseLive X3050’s web management interface allows authentication logic to be performed entirely on the client side, relying on hardcoded values within browser-executed scripts rather than server-side verification. An attacker with access to the login page could retrieve these exposed parameters and gain unauthorized access to administrative functionality.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
使用硬编码的凭证
Vulnerability Title
SenseLive X3050 信任管理问题漏洞
Vulnerability Description
SenseLive X3050是日本SenseLive公司的一款面向物联网场景的数据采集与环境监测设备。 SenseLive X3050存在信任管理问题漏洞,该漏洞源于Web管理界面身份验证逻辑完全在客户端执行,依赖硬编码值,可能导致攻击者获取暴露参数并未经授权访问管理功能。
CVSS Information
N/A
Vulnerability Type
N/A