Unrated severityNVD Advisory· Published Mar 4, 2026· Updated Mar 5, 2026
Authenticated OS Command Injection via Traceroute Utility leads to Root RCE
CVE-2026-28774
Description
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe | operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.
Affected products
2- Range: = 101
- International Datacasting Corporation (IDC)/SFX Series SuperFlex SatelliteReceiver Web Management Interfacev5Range: 101
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.