← Voltar para CVEs
CVE-2026-28777
CRITICAL9.8
Descricao
International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado3/4/2026
Ultima modificacao3/17/2026
Fontenvd
Avistamentos honeypot0
Produtos afetados
datacast:sfx2100datacast:sfx2100_firmware
Fraquezas (CWE)
CWE-798
Referencias
https://www.abdulmhsblog.com/posts/sfx2100-vulns/(b7efe717-a805-47cf-8e9a-921fca0ce0ce)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.