{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ics-advisory/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Satel Netco Design (\u003c v2.1.7)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","industrial-control-system","ics-advisory"],"_cs_type":"advisory","_cs_vendors":["Satel"],"content_html":"\u003cp\u003eSatel Netco Design versions prior to v2.1.7 are susceptible to a suite of four vulnerabilities that, when combined, present a significant risk to communications infrastructure. These vulnerabilities include two instances of relative path traversal (CVE-2026-105275, CVE-2026-101024), a stored cross-site scripting (XSS) vulnerability (CVE-2026-105269), and an inefficient regular expression complexity flaw (CVE-2026-104628).\u003c/p\u003e\n\u003cp\u003eThe path traversal vulnerabilities in the data import and export functions permit authenticated users with Viewer privileges to access restricted file paths and write attacker-controlled content to the application's file system. This capability, particularly within the export function, may lead to remote code execution by overwriting legitimate application files. The XSS vulnerability allows for script execution in the context of other users' sessions, and the regex flaw can be leveraged to cause denial-of-service by consuming excessive system resources. Defenders should prioritize patching to version 2.1.7 to mitigate these high-severity risks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities could result in full system compromise, unauthorized file creation or modification, application-level denial-of-service, and the execution of arbitrary scripts in the browser of other users. These vulnerabilities target the communications sector globally, potentially allowing an authenticated attacker to pivot from limited Viewer or Operator access to elevated control over the affected device.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Satel Netco Design to version 2.1.7 immediately to address the vulnerabilities identified in CVE-2026-105269, CVE-2026-104628, CVE-2026-105275, and CVE-2026-101024.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Netco Design management interface to trusted internal networks to mitigate the impact of unauthorized access by authenticated users.\u003c/li\u003e\n\u003cli\u003eImplement monitoring on application service file system changes to detect anomalous file creation or modification attempts originating from the application process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T17:06:24Z","date_published":"2026-10-08T17:06:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-satel-netco-design/","summary":"Satel Netco Design versions prior to v2.1.7 contain multiple vulnerabilities, including path traversal, XSS, and regex-based DoS, which could be chained by an authenticated user for unauthorized file modification and remote code execution.","title":"Multiple Vulnerabilities in Satel Netco Design","url":"https://feed.craftedsignal.io/briefs/2026-10-satel-netco-design/"}],"language":"en","title":"CraftedSignal Threat Feed - Ics-Advisory","version":"https://jsonfeed.org/version/1.1"}