CRITICAL🇵🇱 Wersja polska

CVE-2026-28774

CVSS 9.3v4.0pub. 2026-03-04upd. 2026-03-09

An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe `|` operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.

🤖 AI Analysis
How it works

The vulnerability (CWE-78) results from insufficient validation and sanitization of input data passed to the 'flags' parameter in the web-based Traceroute tool. An attacker can inject special shell metacharacters, such as the pipe operator '|', which are not filtered before being passed to the operating system. As a result, the shell interpreter executes additional arbitrary OS commands appended by the attacker. These commands are executed with root privileges, giving full control over the device.

Impact

An authenticated attacker gains the ability to execute arbitrary operating system commands with root privileges, resulting in complete takeover of the device and potential compromise of the satellite infrastructure to which the device is connected.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until the fix is implemented, it is recommended to restrict access to the Web Management Interface only to trusted hosts and implement strong authentication and network segmentation.

Who is affected

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver — firmware version 101 (product: SFX2100)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Datacast Sfx2100

    HW
    Datacast
    all versions
  • Datacast Sfx2100 Firmware

    OS
    Datacast
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-29127CRITICAL9.2PL ✓same product

IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation

CVE-2026-28777CRITICAL9.2PL ✓same product

Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH

CVE-2026-28775CRITICAL10.0PL ✓same product

RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex

CVE-2026-28773CRITICAL9.3PL ✓same product

Command injection w narzędziu diagnostycznym Ping urządzenia IDC SFX2100

CVE-2026-29120CRITICAL9.2PL ✓same product

Hardcoded root password hash w firmware IDC SFX2100 — privilege escalation