VYPR
advisoryPublished Oct 8, 2026· 1 source

CISA Warns of Multiple Vulnerabilities in Satel Netco Design

CISA has issued an advisory detailing three critical vulnerabilities in Satel Netco Design, versions prior to v2.1.7, including cross-site scripting, denial of service, and path traversal flaws.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory highlighting several significant vulnerabilities affecting Satel Netco Design software, specifically versions prior to v2.1.7. These flaws, if exploited, could allow attackers to execute arbitrary scripts, cause denial-of-service conditions, and gain unauthorized access to sensitive files.

The advisory details three distinct vulnerability types. The first, identified as CVE-2026-105269, is a stored cross-site scripting (XSS) vulnerability. This flaw allows an authenticated user with Network Operator privileges to inject malicious scripts into the application, which can then be executed in the browsers of other users when they view the compromised content. The CVSS v3.1 score for this vulnerability is 6.8 (MEDIUM), while the CVSS v4.0 score is 8.8 (HIGH), indicating a significant risk.

Another critical vulnerability, CVE-2026-104628, stems from inefficient regular expression complexity. An authenticated user with Viewer privileges can exploit this by submitting specially crafted input that causes the application to consume excessive system resources, potentially leading to a denial-of-service (DoS) condition and impacting the availability of the system. This vulnerability has a CVSS v3.1 score of 6.5 (MEDIUM) and a CVSS v4.0 score of 7.1 (HIGH).

The third category of vulnerabilities involves relative path traversal, affecting both data import and export functionalities. CVE-2026-105275, related to data import, allows authenticated users with Viewer privileges to access file paths outside of the intended directory. CVE-2026-101024, concerning data export, enables authenticated users to write attacker-influenced content to file system locations accessible by the application service. Successful exploitation of these path traversal flaws can lead to unauthorized file access, modification, and in some cases, arbitrary code execution. The CVSS v3.1 score for CVE-2026-101024 is 8.8 (HIGH), with a CVSS v4.0 score of 8.7 (HIGH).

These vulnerabilities were reported to CISA by Alex Williams of Pellera Technologies. The affected product, Satel Netco Design, is used in critical infrastructure sectors, including communications, and is deployed worldwide. The company's headquarters are located in Finland.

Satel has addressed these issues by releasing version v2.1.7 of its Netco Design software. The vendor strongly advises all users to update to this latest version to mitigate the risks associated with these vulnerabilities. CISA recommends that organizations minimize network exposure for all control system devices and ensure they are not directly accessible from the internet.

Further defensive measures include locating control system networks behind firewalls and isolating them from business networks. When remote access is necessary, secure methods such as Virtual Private Networks (VPNs) should be employed, ensuring that VPNs themselves are kept up-to-date. CISA also emphasizes the importance of performing thorough impact analyses and risk assessments before implementing any defensive measures.

The combination of XSS, DoS, and path traversal vulnerabilities presents a multi-faceted threat, potentially allowing attackers to compromise user sessions, disrupt operations, and gain deep access to system files. The ability to execute arbitrary code, especially through path traversal in export functions, poses the most severe risk, potentially leading to full system compromise.

Synthesized by Vypr AI