An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe `|` operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.
The vulnerability (CWE-78) results from insufficient validation and sanitization of input data passed to the 'flags' parameter in the web-based Traceroute tool. An attacker can inject special shell metacharacters, such as the pipe operator '|', which are not filtered before being passed to the operating system. As a result, the shell interpreter executes additional arbitrary OS commands appended by the attacker. These commands are executed with root privileges, giving full control over the device.
An authenticated attacker gains the ability to execute arbitrary operating system commands with root privileges, resulting in complete takeover of the device and potential compromise of the satellite infrastructure to which the device is connected.
Apply patches available from the manufacturer according to the references. Until the fix is implemented, it is recommended to restrict access to the Web Management Interface only to trusted hosts and implement strong authentication and network segmentation.
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver — firmware version 101 (product: SFX2100)
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDatacast Sfx2100
HWDatacastall versionsDatacast Sfx2100 Firmware
OSDatacastall versions
Related vulnerabilities
IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation
Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH
RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex
Command injection w narzędziu diagnostycznym Ping urządzenia IDC SFX2100
Hardcoded root password hash w firmware IDC SFX2100 — privilege escalation