CVE-2026-28774
EUVD-2026-936904.03.2026, 08:16
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe `|` operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| datacast | sfx2100_firmware | - |
𝑥
= Vulnerable software versions