CVE-2026-105275: Satel Netco Design Relative Path Traversal
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data import functionality. An authenticated user with Viewer privileges could access file paths outside the intended directory and use observable application responses to determine whether files exist on the host system.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Satel Netco Designto a version that resolves this vulnerability.Fixed in 2.1.7
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to Satel Netco Design and have Viewer privileges. The vulnerable functionality is the application's data import feature.
What information could be exposed?
The issue allows access attempts to paths outside the intended directory. Observable application responses can reveal whether files exist on the host system; the provided data does not indicate that file contents can be read.
Which versions are affected?
Satel Netco Design versions prior to v2.1.7 are affected. Version v2.1.7 is not identified as affected by the provided information.