← Zuruck zu CVEs
CVE-2026-28777
CRITICAL9.8
Beschreibung
International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/4/2026
Zuletzt geandert3/17/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
datacast:sfx2100datacast:sfx2100_firmware
Schwachen (CWE)
CWE-798
Referenzen
https://www.abdulmhsblog.com/posts/sfx2100-vulns/(b7efe717-a805-47cf-8e9a-921fca0ce0ce)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.