Critical severity9.8NVD Advisory· Published Mar 4, 2026· Updated Jun 17, 2026
CVE-2026-28778
CVE-2026-28778
Description
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the xd user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the xd user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by xdstartstop) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:*
- Range: SFX2100
Patches
Vulnerability mechanics
References
1- www.abdulmhsblog.com/posts/sfx2100-vulns/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.