CVE-2026-28776: Hardcoded and Insecure Credentials for "monitor" account with SSH Access On IDC SFX2100 Satellite Receiver
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the monitor account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28776?
CVE-2026-28776 is considered a high severity vulnerability due to hardcoded and insecure credentials that expose SSH access.
How do I fix CVE-2026-28776?
To fix CVE-2026-28776, remove the hardcoded credentials and implement secure authentication methods for the 'monitor' account.
What are the potential risks of CVE-2026-28776?
The risks of CVE-2026-28776 include unauthorized access to the device's SSH interface and the potential for remote code execution.
Is CVE-2026-28776 easy to exploit?
Yes, CVE-2026-28776 is easy to exploit as it involves using trivial hardcoded credentials that do not require authentication.
Which devices are affected by CVE-2026-28776?
CVE-2026-28776 affects the International Datacasting Corporation SFX Series SuperFlex SatelliteReceiver.