---
id: CVE-2026-5703
title: >-
  Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200,
  specifically in the web portal provided by the device, which allows an
  authenticated user to read any file or list any directory accessible to the
  system user …
summary: >-
  Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200,
  specifically in the web portal provided by the device, which allows an
  authenticated user to read any file or list any directory accessible to the
  system user …
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-35
vendor: Satel Iberia
product: SenNet Datalogger Serie 200
affected:
  - sennet_datalogger_serie_200 V7.0m-1.53h
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T09:17:05.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5703'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/path-traversal-satel-iberia-sennet-datalogger-serie-200
    label: cve-coordination@incibe.es
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-07T09:22:30.529Z'
---

## Overview

Path traversal vulnerability in the Satel Iberia SenNet Datalogger Serie 200, specifically in the web portal provided by the device, which allows an authenticated user to read any file or list any directory accessible to the system user running the web server. This is possible by modifying the URL to include a path traversal payload. Successful exploitation of this vulnerability could allow an attacker to access critical system files containing confidential information.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
