{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-5703", "assignerOrgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "state": "PUBLISHED", "assignerShortName": "INCIBE", "dateReserved": "2026-04-06T12:50:25.930Z", "datePublished": "2026-10-07T08:35:00.317Z", "dateUpdated": "2026-10-07T18:06:27.110Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "0cbda920-cd7f-484a-8e76-bf7f4b7f4516", "shortName": "INCIBE", "dateUpdated": "2026-10-07T08:35:00.317Z" }, "title": "Path Traversal in Satel Iberia SenNet Datalogger Serie 200", "datePublic": "2026-10-07T08:15:00.000Z", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-35", "description": "CWE-35 Path traversal: '.../...//'", "type": "CWE" } ] } ], "affected": [ { "vendor": "Satel Iberia", "product": "SenNet Datalogger Serie 200", "versions": [ { "status": "affected", "version": "V7.0m-1.53h" } ], "defaultStatus": "unaffected" } ], "cpeApplicability": [ { "operator": "OR", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:satel_iberia:sennet_datalogger_serie_200:v7.0m-1.53h:*:*:*:*:*:*:*" } ] } ] } ], "descriptions": [ { "lang": "en", "value": "Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information." } ] } ], "references": [ { "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/path-traversal-satel-iberia-sennet-datalogger-serie-200" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 7.1, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } } ], "solutions": [ { "lang": "en", "value": "The vulnerability has been fixed by Satel Iberia team in version V7.2a.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "The vulnerability has been fixed by Satel Iberia team in version V7.2a." } ] } ], "credits": [ { "lang": "en", "value": "rijndael86", "type": "finder" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T18:04:50.818494Z", "id": "CVE-2026-5703", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T18:06:27.110Z" } } ] } }