Junglewise Threat Intelligence

CVE-2025-10465: Birtech Sensaway unrestricted file upload leading to web shell deployment

CVE-2025-10465 · Severity: high · CVSS 8.8 · Published 2026-02-09

Executive brief

Birtech Sensaway, a monitoring and management solution, contains a security flaw that allows users to upload malicious files to the server. An attacker with basic user access can exploit this to install a 'web shell,' granting them full control over the system and the ability to access sensitive data or disrupt operations. The manufacturer has stated they cannot fix this issue due to the product's outdated technology, meaning the vulnerability will remain permanent for current users.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in Birtech Sensaway through version 09022026. The application fails to properly validate or restrict the types of files uploaded to the web server, allowing an authenticated attacker with low privileges to upload executable scripts (web shells). Once uploaded, these scripts can be executed via the network to achieve remote code execution (RCE), leading to full system compromise. The vendor has officially stated that the product is built on legacy technology and no patch will be released; users are advised to migrate to newer product lines.

Affected products

  • Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway through 09022026

Timeline

  • 2026-02-09: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-02-09: advisory: NVD publication date

References