Relative Path Traversal Vulnerability in Satel Netco Design
CVE-2026-105275

5.3MEDIUM

Key Information:

Vendor

Satel

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105275?

Satel Netco Design versions prior to 2.1.7 have a vulnerability that allows an authenticated user with Viewer privileges to exploit the data import functionality. This relative path traversal flaw could enable users to access files outside of the intended directory. By taking advantage of application responses, they can ascertain which files exist on the host system, potentially leading to unauthorized access to sensitive information.

Affected Version(s)

Satel Netco Design 0

Satel Netco Design v2.1.7

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alex Williams of Pellera Technologies reported this vulnerability to CISA.
.