CVE-2026-29121

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system and may potentially lead to other avenues for preforming privileged actions.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*

History

11 Mar 2026, 18:35

Type Values Removed Values Added
CPE cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://gtfobins.org/gtfobins/ip/ - () https://gtfobins.org/gtfobins/ip/ - Exploit
References () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Datacast
Datacast sfx2100
Datacast sfx2100 Firmware
Summary
  • (es) El receptor de satélite International Data Casting (IDC) SFX2100 viene con la utilidad `/sbin/ip` instalada con el bit setuid establecido. Esta configuración otorga privilegios elevados a cualquier usuario local que pueda ejecutar el binario. Un actor local puede usar el recurso GTFObins para realizar lecturas de archivos privilegiadas como el usuario root en el sistema de archivos local y puede potencialmente conducir a otras vías para realizar acciones privilegiadas.

05 Mar 2026, 06:16

Type Values Removed Values Added
References
  • {'url': 'https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/', 'source': 'b7efe717-a805-47cf-8e9a-921fca0ce0ce'}
  • () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ -

05 Mar 2026, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 01:15

Updated : 2026-03-11 18:35


NVD link : CVE-2026-29121

Mitre link : CVE-2026-29121

CVE.ORG link : CVE-2026-29121


JSON object : View

Products Affected

datacast

  • sfx2100
  • sfx2100_firmware
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo