Relative Path Traversal Vulnerability in Satel Netco Design
CVE-2026-105275
5.3MEDIUM
What is CVE-2026-105275?
Satel Netco Design versions prior to 2.1.7 have a vulnerability that allows an authenticated user with Viewer privileges to exploit the data import functionality. This relative path traversal flaw could enable users to access files outside of the intended directory. By taking advantage of application responses, they can ascertain which files exist on the host system, potentially leading to unauthorized access to sensitive information.
Affected Version(s)
Satel Netco Design 0
Satel Netco Design v2.1.7
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex Williams of Pellera Technologies reported this vulnerability to CISA.
