CVE-2026-28772: Reflected XSS in IDC_Logging Index endpoint
A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDCLogging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101 allows a remote attacker to execute arbitrary web scripts or HTML. The vulnerability is triggered by sending a crafted payload through the submitType parameter, which is reflected directly into the DOM without proper escaping.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28772?
CVE-2026-28772 has a high severity rating due to its potential for exploitation through reflected XSS.
How do I fix CVE-2026-28772?
To fix CVE-2026-28772, update the International Datacasting Corporation SFX Series SuperFlex SatelliteReceiver Web Management Interface to the latest version.
What is the impact of CVE-2026-28772?
The impact of CVE-2026-28772 allows an attacker to execute arbitrary scripts in the context of the affected user's browser.
Who is affected by CVE-2026-28772?
CVE-2026-28772 affects users of the International Datacasting Corporation SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101.
How can I determine if my system is vulnerable to CVE-2026-28772?
You can determine if your system is vulnerable to CVE-2026-28772 by checking if you are running the affected version of the SFX Series SuperFlex SatelliteReceiver Web Management Interface.