CVE-2025-10465

Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server.This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.
Configurations

No configuration.

History

09 Mar 2026, 12:16

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de carga irrestricta de archivo con tipo peligroso en Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway permite cargar una Web Shell a un servidor web. Este problema afecta a Sensaway: hasta el 09022026. NOTA: Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.
Summary (en) Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server.This issue affects Sensaway: through 09022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server.This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.

09 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 14:16

Updated : 2026-03-09 12:16


NVD link : CVE-2025-10465

Mitre link : CVE-2025-10465

CVE.ORG link : CVE-2025-10465


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type