CRITICAL🇵🇱 Wersja polska

CVE-2026-28773

CVSS 9.3v4.0pub. 2026-03-04upd. 2026-03-09

The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr` parameter. An authenticated attacker can bypass server-side semicolon exclusion checks by using alternate shell metacharacters (such as the pipe `|` operator) to append and execute arbitrary shell commands with root privileges.

🤖 AI Analysis
How it works

The vulnerability is located in the CGI script of the Ping diagnostic tool available at the path /IDC_Ping/main.cgi. The application improperly processes the `IPaddr` parameter — although semicolon (`;`) filtering is implemented on the server side, this protection can be bypassed using alternative shell metacharacters such as the pipe operator (`|`). An attacker, after authenticating to the web interface, can inject and execute arbitrary system commands that will be executed with root privileges.

Impact

An attacker can gain full control of the device by executing arbitrary commands with root privileges, enabling configuration modifications, malicious software installation, and lateral movement within the network.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict access to the web management interface only to trusted networks or IP addresses and implement multi-factor authentication where possible.

Who is affected

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver, firmware version 101 (product: Datacast SFX2100 / SFX2100 Firmware)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Datacast Sfx2100

    HW
    Datacast
    all versions
  • Datacast Sfx2100 Firmware

    OS
    Datacast
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-29127CRITICAL9.2PL ✓same product

IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation

CVE-2026-28777CRITICAL9.2PL ✓same product

Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH

CVE-2026-28775CRITICAL10.0PL ✓same product

RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex

CVE-2026-28774CRITICAL9.3PL ✓same product

Command Injection w narzędziu Traceroute interfejsu IDC SFX2100

CVE-2026-29120CRITICAL9.2PL ✓same product

Hardcoded root password hash w firmware IDC SFX2100 — privilege escalation