IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Satel Netco Design

HIGH
CVSS 8.8
Date 2026-10-08T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-105275 4.3 medium
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system.
CVE-2026-105269 6.8 medium
Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.
CVE-2026-104628 6.5 medium
Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability. An authenticated user with Viewer privileges could submit crafted search input that causes excessive processing, potentially degrading the availability of the application.
CVE-2026-101024 8.8 high
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.

// Remediations (1)

Patch: Satel advises users to update to Satel Netco Design v2.1.7.
Satel advises users to update to Satel Netco Design v2.1.7.

// References