vuln-advisoryregulatorNewsThe Broadside1 min read

Satel Netco Design flaws include path traversal, XSS, ReDoS

The most severe of the four vulnerabilities (a path traversal in data export) carries a CVSS 3.1 score of 8.8 and can, under certain conditions, lead to arbitrary code execution.


TL;DR

CISA published an advisory covering four vulnerabilities in Satel Netco Design versions prior to v2.1.7. The flaws span stored cross-site scripting (CVE-2026-105269), inefficient regex complexity that can degrade availability (CVE-2026-104628), relative path traversal in data import that enables file enumeration (CVE-2026-105275), and relative path traversal in data export that can result in unauthorized file creation, modification, and (under certain conditions) arbitrary code execution (CVE-2026-101024, CVSS 3.1: 8.8). Satel advises updating to v2.1.7. All four require authenticated access; the lowest-barrier CVE needs only Viewer privileges. No known public exploitation has been reported to CISA.

Satel's Netco Design is deployed in communications infrastructure worldwide, with company headquarters in Finland. The advisory, released October 8, 2026, was reported by Alex Williams of Pellera Technologies.

The standout vulnerability is CVE-2026-101024, a relative path traversal in the data export function. An authenticated user with Viewer privileges (the lowest role tier) can write attacker-controlled content to filesystem locations accessible to the application service. The CVSS 3.1 score lands at 8.8 (HIGH), with a 4.0 score of 8.7. The vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates network-accessible attack with low complexity and no user interaction, yielding high impacts across confidentiality, integrity, and availability. Under certain conditions, CISA notes, exploitation can result in arbitrary code execution.

The remaining three vulnerabilities are less severe individually but widen the attack surface. CVE-2026-105269 is a stored XSS requiring Network Operator privileges, an attacker could inject untrusted content that executes scripts in another user's browser (CVSS 3.1: 6.8). CVE-2026-104628 is an inefficient regular expression that lets a Viewer craft search input causing excessive processing and potential application denial of service (CVSS 3.1: 6.5). CVE-2026-105275 is a path traversal in the data import function that permits file enumeration through observable application responses (CVSS 3.1: 4.3).

The patch is straightforward in principle: update to v2.1.7. But the advisory doesn't address timeline for patch deployment in production communications environments, where taking a network management platform offline requires coordination. CISA's standard ICS defensive measures apply, minimize network exposure, isolate control system networks from business networks, and use VPNs with current patches for any remote access. Organizations should perform their own impact analysis and risk assessment before deploying mitigations.


Published ·Deep Fathom