← Vulnerability feed

Vulnerability record · CVE-2026-29119 · published 4 March 2026

CVE-2026-29119: Datacast sfx2100 firmware hard-coded credentials vulnerability

Datacast · Sfx2100 Firmware

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

8.8 CVSS 4.0 High EPSS 0.63% · top 52.1% CWE-798 · Hard-coded credentials
8.8CVSS 4.0 base score
0.63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ ExploitThird Party Advisory

Track CVE-2026-29119 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-28775Datacast sfx2100 firmware insecure default initialization vulnerabilityAn unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Sup…EPSS 1.1%9.3CVE-2026-28773Datacast sfx2100 firmware os command injection vulnerabilityThe web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We…EPSS 2.5%9.3CVE-2026-28774Datacast sfx2100 firmware os command injection vulnerabilityAn OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…EPSS 2.9%9.2CVE-2026-29127Datacast sfx2100 firmware improper privilege management vulnerabilityThe IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…EPSS 0.15%9.2CVE-2026-28777Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attac…EPSS 0.63%9.2CVE-2026-29120Datacast sfx2100 firmware hard-coded credentials vulnerabilityThe /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece…EPSS 0.16%8.6CVE-2026-29128Datacast sfx2100 firmware insufficiently protected credentials vulnerabilityIDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…EPSS 0.29%8.6CVE-2026-29123Datacast sfx2100 firmware improper privilege management vulnerabilityA SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially pre…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2026-29119), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.