TROYANOSYVIRUS
Volver a CVEs

CVE-2026-28777

CRITICAL
9.8

Descripcion

International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/4/2026
Ultima modificacion3/17/2026
Fuentenvd
Avistamientos honeypot0

Productos afectados

datacast:sfx2100datacast:sfx2100_firmware

Debilidades (CWE)

CWE-798

Referencias

https://www.abdulmhsblog.com/posts/sfx2100-vulns/(b7efe717-a805-47cf-8e9a-921fca0ce0ce)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.