CVE-2026-28774: Authenticated OS Command Injection via Traceroute Utility leads to Root RCE
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe | operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28774?
CVE-2026-28774 is classified as a critical severity vulnerability due to the potential for root RCE.
How do I fix CVE-2026-28774?
To mitigate CVE-2026-28774, update the web management interface of the affected International Datacasting Corporation product to the latest version.
What systems are affected by CVE-2026-28774?
CVE-2026-28774 affects the International Datacasting Corporation SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101.
What type of vulnerability is CVE-2026-28774?
CVE-2026-28774 is an authenticated OS command injection vulnerability.
What is the impact of CVE-2026-28774?
The impact of CVE-2026-28774 allows an authenticated attacker to execute arbitrary commands on the system, leading to root access.