CVE-2026-28776

International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.
References
Link Resource
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*

History

17 Mar 2026, 16:51

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Datacast
Datacast sfx2100
Datacast sfx2100 Firmware
Summary
  • (es) El receptor de satélite SuperFlex de la serie SFX de International Datacasting Corporation (IDC) contiene credenciales codificadas de forma rígida para la cuenta 'monitor'. Un atacante remoto no autenticado puede usar estas credenciales triviales y no documentadas para acceder al sistema a través de SSH. Aunque inicialmente se le coloca en un shell restringido, el atacante puede evadirse trivialmente para lograr la funcionalidad de shell estándar.
References () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - Exploit, Third Party Advisory
CPE cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*

05 Mar 2026, 06:16

Type Values Removed Values Added
References
  • {'url': 'https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/', 'source': 'b7efe717-a805-47cf-8e9a-921fca0ce0ce'}
  • () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ -

04 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 08:16

Updated : 2026-03-17 16:51


NVD link : CVE-2026-28776

Mitre link : CVE-2026-28776

CVE.ORG link : CVE-2026-28776


JSON object : View

Products Affected

datacast

  • sfx2100
  • sfx2100_firmware
CWE
CWE-798

Use of Hard-coded Credentials