CVE-2026-5703 PUBLISHED

Path Traversal in Satel Iberia SenNet Datalogger Serie 200

Assigner: INCIBE
Reserved: 06.04.2026 Published: 07.10.2026 Updated: 07.10.2026

Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Satel Iberia
Product SenNet Datalogger Serie 200
Versions Default: unaffected
  • Version V7.0m-1.53h is affected

Solutions

The vulnerability has been fixed by Satel Iberia team in version V7.2a.

Credits

  • rijndael86 finder

References

Problem Types

  • CWE-35 Path traversal: '.../...//' CWE