CVE-2026-28776
EUVD-2026-937104.03.2026, 08:16
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| datacast | sfx2100_firmware | - |
𝑥
= Vulnerable software versions