Junglewise Threat Intelligence

CVE-2025-10464: Birtech Senseway insecure storage of sensitive information

CVE-2025-10464 · Severity: medium · CVSS 6.5 · Published 2026-02-09

Executive brief

Birtech Senseway, a monitoring and management solution, contains a vulnerability where sensitive information is stored insecurely. This flaw allows an authenticated user to retrieve embedded sensitive data that should otherwise be protected. Because the product is built on legacy technology, the manufacturer is unable to provide a security patch, potentially leaving customer data or system credentials exposed indefinitely.

Technical details

Birtech Senseway is vulnerable to insecure storage of sensitive information (CWE-312, CWE-922). The flaw allows a network-based attacker with low-level authentication to retrieve embedded sensitive data from the application. The root cause is attributed to the use of outdated underlying technology in the product's development. The manufacturer has stated they are unable to fix the vulnerability due to these technical limitations. Users are advised to migrate to newer products as all versions through February 2026 are impacted.

Affected products

  • Birtech Information Technologies Industry and Trade Ltd. Co. Senseway through 09022026

Timeline

  • 2026-02-09: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-02-09: advisory: NVD publication date

References

Related threats