Datacast
Datacast Sfx2100 Firmware: vulnerabilidades y CVE
Datacast Sfx2100 Firmware tiene 20 vulnerabilidades publicadas, 20 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE20
Últimos 12 meses20
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-29128 | Alta (8.6) | 0.30% | — | 5 mar 2026 | IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files… |
| CVE-2026-29127 | Crítica (9.2) | 0.15% | — | 5 mar 2026 | The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all… |
| CVE-2026-29126 | Alta (8.5) | 0.17% | — | 5 mar 2026 | Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary… |
| CVE-2026-29125 | Alta (7.1) | 0.11% | — | 5 mar 2026 | IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and… |
| CVE-2026-29124 | Alta (8.6) | 0.14% | — | 5 mar 2026 | Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC)… |
| CVE-2026-29123 | Alta (8.6) | 0.14% | — | 5 mar 2026 | A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system… |
| CVE-2026-29122 | Alta (8.3) | 0.15% | — | 5 mar 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the… |
| CVE-2026-29121 | Alta (8.3) | 0.15% | — | 5 mar 2026 | International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the… |
| CVE-2026-29120 | Crítica (9.2) | 0.16% | — | 4 mar 2026 | The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password… |
| CVE-2026-29119 | Alta (8.8) | 0.65% | — | 4 mar 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these… |
| CVE-2026-28778 | Alta (7.9) | 0.83% | — | 4 mar 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP… |
| CVE-2026-28777 | Crítica (9.2) | 0.65% | — | 4 mar 2026 | International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system,… |
| CVE-2026-28776 | Alta (7.8) | 0.65% | — | 4 mar 2026 | International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented… |
| CVE-2026-28775 | Crítica (10) | 1.1% | — | 4 mar 2026 | An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the… |
| CVE-2026-28774 | Crítica (9.3) | 3.0% | — | 4 mar 2026 | An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An… |
| CVE-2026-28773 | Crítica (9.3) | 2.6% | — | 4 mar 2026 | The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101 is vulnerable to OS Command… |
| CVE-2026-28772 | Media (5.1) | 0.32% | — | 4 mar 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101… |
| CVE-2026-28771 | Media (5.1) | 0.32% | — | 4 mar 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101. The… |
| CVE-2026-28770 | Media (5.3) | 0.57% | — | 4 mar 2026 | Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows… |
| CVE-2026-28769 | Media (5.3) | 0.82% | — | 4 mar 2026 | A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 101. An authenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.