Executive brief
Sayax Energy Technologies OSOS, a system used for energy management and automated meter reading, contains a security flaw that leaks sensitive information. This vulnerability could allow an unauthorized individual to bypass authentication mechanisms and gain access to the system. Such an exploit could lead to the exposure of energy consumption data or unauthorized access to utility management functions.
Technical details
A vulnerability classified as CWE-201 (Insertion of Sensitive Information Into Sent Data) exists in Sayax Energy Technologies Inc. OSOS through version 09072026. The application inadvertently includes sensitive data in its network responses, which can be leveraged by a remote attacker to bypass authentication procedures. The attack requires low privileges and is reachable over the network with no user interaction required. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.
Affected products
- Sayax Energy Technologies Inc. OSOS through 09072026
Timeline
- 2026-07-09: advisory: Initial disclosure by TR-CERT
- 2026-07-09: disclosed: Vendor was contacted but did not respond.