Description
Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
The vulnerability has been fixed by Satel Iberia team in version V7.2a.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 07 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information. | |
| Title | Path Traversal in Satel Iberia SenNet Datalogger Serie 200 | |
| First Time appeared |
Satel Iberia
Satel Iberia sennet Datalogger Serie 200 |
|
| Weaknesses | CWE-35 | |
| CPEs | cpe:2.3:a:satel_iberia:sennet_datalogger_serie_200:v7.0m-1.53h:*:*:*:*:*:*:* | |
| Vendors & Products |
Satel Iberia
Satel Iberia sennet Datalogger Serie 200 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-10-07T08:35:00.317Z
Reserved: 2026-04-06T12:50:25.930Z
Link: CVE-2026-5703
No data.
Status : Received
Published: 2026-10-07T09:17:05.673
Modified: 2026-10-07T09:17:05.673
Link: CVE-2026-5703
No data.
OpenCVE Enrichment
Updated: 2026-10-07T10:45:07Z
Weaknesses