CVE-2026-105269 PUBLISHED

Satel Netco Design Cross-site Scripting

Assigner: icscert
Reserved: 05.10.2026 Published: 08.10.2026 Updated: 09.10.2026

Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization. Successful exploitation could allow script execution in another user's browser when the affected content is viewed.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Satel
Product Satel Netco Design
Versions Default: unaffected
  • affected from 0 to v2.1.7 (excl.)
  • Version v2.1.7 is unaffected

Solutions

Satel advises users to update to Satel Netco Design v2.1.7.

Credits

  • Alex Williams of Pellera Technologies reported this vulnerability to CISA. finder

References

Problem Types

  • CWE-79 CWE