TROYANOSYVIRUS
Voltar para CVEs

CVE-2026-28777

CRITICAL
9.8

Descricao

International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.

Detalhes CVE

Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado3/4/2026
Ultima modificacao3/17/2026
Fontenvd
Avistamentos honeypot0

Produtos afetados

datacast:sfx2100datacast:sfx2100_firmware

Fraquezas (CWE)

CWE-798

Referencias

https://www.abdulmhsblog.com/posts/sfx2100-vulns/(b7efe717-a805-47cf-8e9a-921fca0ce0ce)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.