VYPR

SFX2100 Satellite Receiver

by IDC

CVEs (3)

  • CVE-2026-29128CriMar 5, 2026
    risk 0.65cvss 10.0epss 0.00

    IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) contain…

  • CVE-2026-28777CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker…

  • CVE-2026-29127HigMar 5, 2026
    risk 0.51cvss 7.8epss 0.00

    The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege…