CVE-2026-29123

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared object hijacking.
References
Link Resource
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*

History

11 Mar 2026, 18:35

Type Values Removed Values Added
First Time Datacast
Datacast sfx2100
Datacast sfx2100 Firmware
CWE NVD-CWE-noinfo
Summary
  • (es) Un binario SUID propiedad de root en /home/xd/terminal/XDTerminal en International Data Casting (IDC) SFX2100 en Linux permite a un actor local realizar potencialmente una escalada de privilegios local dependiendo de las condiciones del sistema mediante la ejecución del binario SUID afectado. Esto puede ser mediante secuestro de PATH, abuso de enlaces simbólicos o secuestro de objetos compartidos.
References () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ - Exploit, Third Party Advisory
CPE cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:*
cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

05 Mar 2026, 06:16

Type Values Removed Values Added
References
  • {'url': 'https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/', 'source': 'b7efe717-a805-47cf-8e9a-921fca0ce0ce'}
  • () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ -

05 Mar 2026, 02:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 02:16

Updated : 2026-03-11 18:35


NVD link : CVE-2026-29123

Mitre link : CVE-2026-29123

CVE.ORG link : CVE-2026-29123


JSON object : View

Products Affected

datacast

  • sfx2100
  • sfx2100_firmware
CWE
CWE-269

Improper Privilege Management

NVD-CWE-noinfo