CVE-2026-28777: Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver
International Datacasting Corporation (IDC)
SFX2100 Satellite Receiver, trivial password for the user (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28777?
CVE-2026-28777 is considered a high-severity vulnerability due to the potential for remote unauthorized access.
How do I fix CVE-2026-28777?
To mitigate CVE-2026-28777, change the default password for the 'user' account and implement stronger password policies.
Who is affected by CVE-2026-28777?
The CVE-2026-28777 vulnerability affects users of the International Datacasting Corporation SFX2100 Satellite Receiver.
What is the exploit method for CVE-2026-28777?
CVE-2026-28777 can be exploited through remote SSH access using hardcoded and trivial credentials.
What impact does CVE-2026-28777 have on systems?
CVE-2026-28777 allows unauthorized users to gain complete control over the affected satellite receiver systems.