CVE-2026-28778: Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the xd user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the xd user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by xdstartstop) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28778?
CVE-2026-28778 is considered critical due to the presence of hardcoded FTP credentials and local privilege escalation vulnerability.
How do I fix CVE-2026-28778?
To fix CVE-2026-28778, update the SFX Series SuperFlex Satellite Receiver firmware to a version that removes hardcoded credentials and implements secure permissions.
Who is affected by CVE-2026-28778?
The vulnerability CVE-2026-28778 affects the International Datacasting Corporation SFX Series SuperFlex Satellite Receiver.
Can CVE-2026-28778 be exploited remotely?
Yes, CVE-2026-28778 can be exploited remotely by an unauthenticated attacker due to the hardcoded credentials.
What are the implications of CVE-2026-28778?
The implications of CVE-2026-28778 include unauthorized access to the device and potential manipulation of its functionalities due to local privilege escalation.