{"id":"CVE-2026-5703","title":"Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user …","summary":"Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user …","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-35"],"vendor":"Satel Iberia","product":"SenNet Datalogger Serie 200","affected":["sennet_datalogger_serie_200 V7.0m-1.53h"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T09:17:05.673","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5703","references":[{"url":"https://www.incibe.es/en/incibe-cert/notices/aviso/path-traversal-satel-iberia-sennet-datalogger-serie-200","label":"cve-coordination@incibe.es"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T09:22:30.529Z","slug":"CVE-2026-5703","body":"## Overview\n\nPath traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}