CVE-2026-28778 Details
Description
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by `xdstartstop`) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.
A vulnerability exists in the International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver due to undocumented, hardcoded credentials for the 'xd' user account. This flaw allows remote, unauthenticated attackers to log in via FTP and gain write access to the user's home directory. The 'xd' user has permissions to modify files and symlinks related to root-executed binaries, such as those controlled by 'xdstartstop'. Exploiting this vulnerability could lead to arbitrary code execution with root privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.abdulmhsblog.com/posts/sfx2100-vulns/ | Gridware | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | Gridware |
Affected Products
| Product | Versions |
|---|---|
| datacast sfx2100 firmware | All versions |
CPE
Remediation
| |
| datacast sfx2100 | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Gridware |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 5, 2026 | CVE Modified | Gridware |
| Mar 4, 2026 | New CVE Received | Gridware |