CVE-2026-28777 Details
Description
International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
A vulnerability exists in the International Datacasting Corporation (IDC) SFX2100 Satellite Receiver due to a trivial password for the 'user' (usr) account. This flaw allows remote, unauthenticated attackers to gain unauthorized SSH access to the system. Although initially placed in a restricted shell, an attacker can easily spawn a full pseudo-terminal to obtain an interactive shell.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.abdulmhsblog.com/posts/sfx2100-vulns/ | Gridware | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | Gridware |
Affected Products
| Product | Versions |
|---|---|
| datacast sfx2100 firmware | All versions |
CPE
Remediation
| |
| datacast sfx2100 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Gridware |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 5, 2026 | CVE Modified | Gridware |
| Mar 4, 2026 | New CVE Received | Gridware |