← Vulnerability feed

Vulnerability record · CVE-2026-29124 · published 5 March 2026

CVE-2026-29124: Datacast sfx2100 firmware improper privilege management vulnerability

Datacast · Sfx2100 Firmware

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from the `monitor` user to root

8.6 CVSS 4.0 High EPSS 0.13% · top 97.7% CWE-269 · Improper privilege management
8.6CVSS 4.0 base score
0.13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from the `monitor` user to root

CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ ExploitThird Party Advisory

Track CVE-2026-29124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-28775Datacast sfx2100 firmware insecure default initialization vulnerabilityAn unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Sup…EPSS 1.1%9.3CVE-2026-28773Datacast sfx2100 firmware os command injection vulnerabilityThe web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We…EPSS 2.5%9.3CVE-2026-28774Datacast sfx2100 firmware os command injection vulnerabilityAn OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…EPSS 2.9%9.2CVE-2026-29127Datacast sfx2100 firmware improper privilege management vulnerabilityThe IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured w…EPSS 0.15%9.2CVE-2026-28777Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attac…EPSS 0.63%9.2CVE-2026-29120Datacast sfx2100 firmware hard-coded credentials vulnerabilityThe /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece…EPSS 0.16%8.8CVE-2026-29119Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…EPSS 0.63%8.6CVE-2026-29128Datacast sfx2100 firmware insufficiently protected credentials vulnerabilityIDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…EPSS 0.29%

Source: NIST National Vulnerability Database (record CVE-2026-29124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.