Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101024— Satel Netco Design Relative path traversal

Quick assessment

Affected
Satel Satel Netco Design
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Satel Netco Design 版本低于 v2.1.7 的产品在数据导出功能中存在相对路径遍历漏洞。拥有“查看者”(Viewer)权限并经身份验证的用户,可将受攻击者控制的内容写入应用程序服务可访问的文件系统位置。成功利用该漏洞可能导致未经授权的文件创建或修改,并且在某些条件下,可能实现任意代码执行。

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101024

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Satel Netco Design Relative path traversal
Source: CVE Program / CVE List V5
Vulnerability Description
Satel Netco Design versions prior to v2.1.7 contains a relative path traversal vulnerability in its data export functionality. An authenticated user with Viewer privileges could write attacker influenced content to file system locations accessible to the application service. Successful exploitation could result in unauthorized file creation or modification and, under certain conditions, arbitrary code execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
相对路径遍历
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Satel Satel Netco Design 0 ~ v2.1.7 -

II. Public POCs for CVE-2026-101024

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101024

请登录查看更多情报信息。

Other References for CVE-2026-101024 (1)

Same Patch Batch · Satel · 2026-10-08 · 4 CVEs total

CVE-2026-105269 6.8 MEDIUM Satel Netco Design Cross-site Scripting
CVE-2026-104628 6.5 MEDIUM Satel Netco Design Inefficient Regular Expression Complexity
CVE-2026-105275 4.3 MEDIUM Satel Netco Design Relative Path Traversal

IV. Related Vulnerabilities

V. Comments for CVE-2026-101024

No comments yet


Leave a comment