Description
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized file creation or modification with potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

Satel Netco Design versions before 2.1.7 allow an authenticated user with Viewer privileges to exploit a relative path traversal flaw in the data export feature. The flaw enables the attacker to write content influenced by the user to arbitrary file system locations that the application service can access. As a result, the attacker can create or modify files, and in specific circumstances the attacker may achieve arbitrary code execution, compromising both confidentiality and integrity of the system.

Affected Systems

The vulnerability affects Satel Netco Design deployments running any version prior to 2.1.7. Users of the legacy product should verify the exact version of their installation and consider the upgrade path provided by the vendor.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is not currently available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not been widely exploited yet. The attack requires the target to be authenticated with Viewer privileges, limiting the potential attacker base to those who can access the system. Nonetheless, the combination of local authentication and file write capabilities presents a significant risk if an attacker can compromise or elevate a user account.

Generated by OpenCVE AI on October 8, 2026 at 22:23 UTC.

Remediation

Vendor Solution

Satel advises users to update to Satel Netco Design v2.1.7.


OpenCVE Recommended Actions

  • Upgrade Satel Netco Design to version 2.1.7 or later to eliminate the path traversal flaw
  • Restrict Viewer privileges or remove the data export capability for accounts that do not need it
  • Apply input validation or filtering to the data export parameters if an upgrade is temporarily impossible
  • Monitor system logs for unexpected file creation or modification events

Generated by OpenCVE AI on October 8, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.
Title Satel Netco Design Relative path traversal
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-08T21:10:00.961Z

Reserved: 2026-10-05T21:19:46.300Z

Link: CVE-2026-101024

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T21:17:51.240

Modified: 2026-10-08T21:26:32.080

Link: CVE-2026-101024

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T22:30:18Z

Weaknesses
  • CWE-23

    Relative Path Traversal