Executive brief
Birtech Senseway, a monitoring and management solution, contains a vulnerability where sensitive information is stored insecurely. This flaw allows an authenticated user to retrieve embedded sensitive data that should otherwise be protected. Because the product is built on legacy technology, the manufacturer is unable to provide a security patch, potentially leaving customer data or system credentials exposed indefinitely.
Technical details
Birtech Senseway is vulnerable to insecure storage of sensitive information (CWE-312, CWE-922). The flaw allows a network-based attacker with low-level authentication to retrieve embedded sensitive data from the application. The root cause is attributed to the use of outdated underlying technology in the product's development. The manufacturer has stated they are unable to fix the vulnerability due to these technical limitations. Users are advised to migrate to newer products as all versions through February 2026 are impacted.
Affected products
- Birtech Information Technologies Industry and Trade Ltd. Co. Senseway through 09022026
Timeline
- 2026-02-09: disclosed: Initial disclosure by TR-CERT (USOM)
- 2026-02-09: advisory: NVD publication date