{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-10463",
        "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "state": "PUBLISHED",
        "assignerShortName": "TR-CERT",
        "dateReserved": "2025-09-15T06:59:43.208Z",
        "datePublished": "2026-02-09T12:07:31.847Z",
        "dateUpdated": "2026-06-05T08:45:21.856Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
                "shortName": "TR-CERT",
                "dateUpdated": "2026-06-05T08:45:21.856Z"
            },
            "title": "Improper Authentication in Birtech Information Technologies' Sensaway",
            "datePublic": "2026-02-09T12:02:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-287",
                            "description": "CWE-287 Improper Authentication",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-114",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-114 Authentication Abuse"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Birtech Information Technologies Industry and Trade Ltd. Co.",
                    "product": "Senseway",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThanOrEqual": "09022026",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unknown"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.\n\nThis issue affects Senseway: through 09022026. \n\nNOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse.<p>This issue affects Senseway: through 09022026.&nbsp;\n\nNOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities. Users of the Sensaway application are advised to contact the manufacturer and review updated products developed with newer technology.\n\n\n\n</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.usom.gov.tr/bildirim/tr-26-0022",
                    "tags": [
                        "government-resource",
                        "broken-link"
                    ]
                },
                {
                    "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0022",
                    "tags": [
                        "government-resource"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "LOW",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.3,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Abdüssamed GÜZEY",
                    "type": "finder"
                }
            ],
            "source": {
                "defect": [
                    "TR-26-0022"
                ],
                "advisory": "TR-26-0022",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-02-09T12:47:54.118450Z",
                                "id": "CVE-2025-10463",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-02-09T12:49:06.603Z"
                }
            }
        ]
    }
}