The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr` parameter. An authenticated attacker can bypass server-side semicolon exclusion checks by using alternate shell metacharacters (such as the pipe `|` operator) to append and execute arbitrary shell commands with root privileges.
The vulnerability is located in the CGI script of the Ping diagnostic tool available at the path /IDC_Ping/main.cgi. The application improperly processes the `IPaddr` parameter — although semicolon (`;`) filtering is implemented on the server side, this protection can be bypassed using alternative shell metacharacters such as the pipe operator (`|`). An attacker, after authenticating to the web interface, can inject and execute arbitrary system commands that will be executed with root privileges.
An attacker can gain full control of the device by executing arbitrary commands with root privileges, enabling configuration modifications, malicious software installation, and lateral movement within the network.
Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict access to the web management interface only to trusted networks or IP addresses and implement multi-factor authentication where possible.
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver, firmware version 101 (product: Datacast SFX2100 / SFX2100 Firmware)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDatacast Sfx2100
HWDatacastall versionsDatacast Sfx2100 Firmware
OSDatacastall versions
Related vulnerabilities
IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation
Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH
RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex
Command Injection w narzędziu Traceroute interfejsu IDC SFX2100
Hardcoded root password hash w firmware IDC SFX2100 — privilege escalation