# CISA discloses four flaws in Satel Netco Design

Published: 2026-10-08 · Severity: routine · Sectors: telecommunications
Canonical: https://vorant.io/reports/b38d0f53-c75f-5114-94ee-f69662f7e037/cisa-discloses-four-flaws-in-satel-netco-design

> Satel Netco Design before v2.1.7 has four vulnerabilities including stored XSS, DoS via regex, and path traversal; patch available, no known exploitation.

CISA published an ICS advisory covering four vulnerabilities in Satel Netco Design, a product used in the communications sector by the Finnish vendor Satel, deployed worldwide. The flaws range from a stored cross-site scripting issue exploitable by an authenticated Network Operator, to an inefficient regular expression complexity issue allowing authenticated Viewer-level users to degrade application availability through crafted search input. Two relative path traversal vulnerabilities in the data import and export functionality could allow authenticated Viewer-level users to enumerate file existence outside intended directories, or write attacker-influenced content to filesystem locations, potentially leading to unauthorized file creation, modification, or arbitrary code execution.

All four issues affect Satel Netco Design versions prior to v2.1.7, and Satel has released a vendor fix addressing them in that version. Exploitation of these flaws requires authenticated access at Viewer or Network Operator privilege levels, limiting the attack surface to users with some level of existing access or compromised credentials. CISA states no known public exploitation targeting these vulnerabilities has been reported.

Defenders operating Satel Netco Design should prioritize upgrading to v2.1.7 or later, and in the interim apply CISA's standard ICS guidance: minimize internet exposure of control system devices, isolate control networks behind firewalls, and use VPNs for any required remote access. The vulnerabilities were responsibly reported to CISA by Alex Williams of Pellera Technologies.

## Mentioned in this report

- Vulnerabilities: CVE-2026-101024, CVE-2026-104628, CVE-2026-105269, CVE-2026-105275

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-281-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b38d0f53-c75f-5114-94ee-f69662f7e037/cisa-discloses-four-flaws-in-satel-netco-design.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
