CVE-2026-28775

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.
References
Link Resource
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*

History

17 Jun 2026, 10:29

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de ejecución remota de código (RCE) no autenticada en el servicio SNMP de International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. La implementación aprovisiona de forma insegura la cadena de comunidad SNMP 'private' con acceso de lectura/escritura por defecto. Debido a que el agente SNMP se ejecuta como root, un atacante remoto no autenticado puede utilizar directivas 'NET-SNMP-EXTEND-MIB', abusando del hecho de que el sistema ejecuta una versión vulnerable de net-snmp anterior a la 5.8, para ejecutar comandos arbitrarios del sistema operativo con privilegios de root.

09 Mar 2026, 18:24

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - Exploit, Third Party Advisory
First Time Datacast
Datacast sfx2100
Datacast sfx2100 Firmware
CWE NVD-CWE-noinfo
CPE cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*

05 Mar 2026, 06:16

Type Values Removed Values Added
References
  • {'url': 'https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/', 'source': 'b7efe717-a805-47cf-8e9a-921fca0ce0ce'}
  • () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ -

04 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 08:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-28775

Mitre link : CVE-2026-28775

CVE.ORG link : CVE-2026-28775


JSON object : View

Products Affected

datacast

  • sfx2100
  • sfx2100_firmware
CWE
CWE-1188

Insecure Default Initialization of Resource

NVD-CWE-noinfo