CRITICAL🇵🇱 Wersja polska

CVE-2026-28777

CVSS 9.2v4.0pub. 2026-03-04upd. 2026-03-17

International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.

🤖 AI Analysis
How it works

The vulnerability results from the use of a hardcoded, easily guessable password assigned to the 'user' (usr) account in the SFX2100 device firmware (CWE-798). An attacker can remotely log in via SSH without knowledge of any credentials other than this trivial password. Although the session is initially restricted to a restricted shell after login, the attacker can easily launch a full interactive PTY environment, thereby gaining broader access to the system.

Impact

An attacker gains remote, unauthorized access to the device's operating system from an interactive shell session, enabling further system exploration, lateral movement in the network, and potential compromise of satellite infrastructure managed by the device.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Until the patch is implemented, it is recommended to block SSH access to the device at the firewall level, isolate the device in a dedicated network segment, and change the default password for the 'user' account if the firmware allows it.

Who is affected

Datacast SFX2100 Satellite Receiver – firmware (Datacast Sfx2100 Firmware) and Datacast Sfx2100 device; specific firmware versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Datacast Sfx2100

    HW
    Datacast
    all versions
  • Datacast Sfx2100 Firmware

    OS
    Datacast
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-29127CRITICAL9.2PL ✓same product

IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation

CVE-2026-29120CRITICAL9.2PL ✓same product

Hardcoded root password hash w firmware IDC SFX2100 — privilege escalation

CVE-2026-28774CRITICAL9.3PL ✓same product

Command Injection w narzędziu Traceroute interfejsu IDC SFX2100

CVE-2026-28773CRITICAL9.3PL ✓same product

Command injection w narzędziu diagnostycznym Ping urządzenia IDC SFX2100

CVE-2026-28775CRITICAL10.0PL ✓same product

RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex