← Vulnerability feed

Vulnerability record · CVE-2026-29122 · published 5 March 2026

CVE-2026-29122: Datacast sfx2100 firmware improper privilege management vulnerability

Datacast · Sfx2100 Firmware

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system. This allows an actor to be able to read any root read-only files, such as the /etc/shadow file or other configuration/secrets carrier files.

8.3 CVSS 4.0 High EPSS 0.14% · top 97.2% CWE-269 · Improper privilege management
8.3CVSS 4.0 base score
0.14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use the GTFObins resource to preform privileged file reads as the root user on the local file system. This allows an actor to be able to read any root read-only files, such as the /etc/shadow file or other configuration/secrets carrier files.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-29122 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-28775Datacast sfx2100 firmware insecure default initialization vulnerabilityAn unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Sup…EPSS 1.1%9.3CVE-2026-28773Datacast sfx2100 firmware os command injection vulnerabilityThe web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We…EPSS 2.5%9.3CVE-2026-28774Datacast sfx2100 firmware os command injection vulnerabilityAn OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…EPSS 2.9%9.2CVE-2026-29127Datacast sfx2100 firmware improper privilege management vulnerabilityThe IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…EPSS 0.15%9.2CVE-2026-28777Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attac…EPSS 0.63%9.2CVE-2026-29120Datacast sfx2100 firmware hard-coded credentials vulnerabilityThe /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece…EPSS 0.16%8.8CVE-2026-29119Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…EPSS 0.63%8.6CVE-2026-29128Datacast sfx2100 firmware insufficiently protected credentials vulnerabilityIDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2026-29122), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.