CVE-2026-5703
Received Received - Intake

Path Traversal in Satel Iberia SenNet Datalogger Serie 200

Vulnerability report for CVE-2026-5703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)

Description

Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Satel Iberia SenNet Datalogger Serie 200 V7.0m-1.53h

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-35 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200 web portal. An authenticated user can exploit it by modifying the URL to include a path traversal payload, allowing access to any file or directory accessible to the web server user. This could lead to unauthorized access to sensitive system files containing confidential information.

Detection Guidance

Check if your Satel Iberia SenNet Datalogger Serie 200 is running version V7.0m-1.53h or earlier. Inspect web server logs for unusual URL patterns containing path traversal sequences like '../' or '/../'. Test by attempting to access sensitive files via modified URLs such as http://[device-ip]/[path]/../../etc/passwd.

Impact Analysis

An attacker could exploit this to read sensitive files on the device, potentially exposing confidential data like system configurations, user credentials, or other critical information. This could lead to further attacks or data breaches if exploited by unauthorized individuals.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR or HIPAA. Unauthorized access to confidential information could result in legal penalties, data breach notifications, and reputational damage for affected organizations.

Mitigation Strategies

Update the device firmware to version V7.2a or later as provided by Satel Iberia. Restrict network access to the device's web portal to trusted users only. Monitor for unauthorized file access attempts in logs. Disable or restrict directory listing functionality if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart