CVE-2026-28776
Published: Mar 4, 2026
Modified: Mar 5, 2026
Description
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.
| Vendor | Product | Versions |
|---|---|---|
International Datacasting Corporation (IDC) | IDC SFX2100 SuperFlex Satellite Receiver | affected SFX2100 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now