CRITICAL🇵🇱 Wersja polska

CVE-2026-29120

CVSS 9.2v4.0pub. 2026-03-04upd. 2026-03-17

The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and susceptible to offline dictionary attacks using the rockyou.txt wordlist. Because direct root SSH login is disabled, an attacker must first obtain low-privileged access to the system (e.g., via other vulnerabilities) to be able to log in as the root user. The password is hardcoded and so allows for an actor with local access on effected versions to escalate to root

🤖 AI Analysis
How it works

The file /root/anaconda-ks.cfg contains a hardcoded root user password hash. This password is simple enough to be cracked offline using popular wordlists such as rockyou.txt. Since direct root login via SSH is disabled, an attacker must first obtain access with low privileges (e.g., through other vulnerabilities), and then use the recovered password to escalate privileges to the root account.

Impact

An attacker with local, unprivileged access to the system can take full control of the device as root, obtaining unlimited access to its resources and configuration, as well as to connected systems (high impact on confidentiality and integrity in system context).

Mitigation & patch

Apply patches available from the manufacturer according to references. As interim measures, it is recommended to change the default root password to a strong, unique password and restrict local access to the device to trusted users only. The file /root/anaconda-ks.cfg should be secured or deleted.

Who is affected

International Datacasting Corporation (IDC) SFX2100 SuperFlex Satellite Receiver — Datacast SFX2100 firmware (versions indicated in manufacturer references)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Datacast Sfx2100

    HW
    Datacast
    all versions
  • Datacast Sfx2100 Firmware

    OS
    Datacast
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-29127CRITICAL9.2PL ✓same product

IDC SFX2100: błędne uprawnienia katalogu umożliwiają privilege escalation

CVE-2026-28777CRITICAL9.2PL ✓same product

Hardcoded hasło w urządzeniu IDC SFX2100 – nieautoryzowany dostęp SSH

CVE-2026-28774CRITICAL9.3PL ✓same product

Command Injection w narzędziu Traceroute interfejsu IDC SFX2100

CVE-2026-28773CRITICAL9.3PL ✓same product

Command injection w narzędziu diagnostycznym Ping urządzenia IDC SFX2100

CVE-2026-28775CRITICAL10.0PL ✓same product

RCE jako root przez SNMP w odbiorniku IDC SFX Series SuperFlex