← Vulnerability feed

Vulnerability record · CVE-2026-29127 · published 5 March 2026

CVE-2026-29127: Datacast sfx2100 firmware improper privilege management vulnerability

Datacast · Sfx2100 Firmware

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged processes and binaries residing within the affected directory.

9.2 CVSS 4.0 Critical EPSS 0.15% · top 96.7% CWE-269 · Improper privilege managementCWE-863 · Incorrect authorization
9.2CVSS 4.0 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged processes and binaries residing within the affected directory.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ ExploitThird Party Advisory
https://www.abdulmhsblog.com/posts/sfx2100-vulns/ ExploitThird Party Advisory

Track CVE-2026-29127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-28775Datacast sfx2100 firmware insecure default initialization vulnerabilityAn unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series Sup…EPSS 1.1%9.3CVE-2026-28773Datacast sfx2100 firmware os command injection vulnerabilityThe web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver We…EPSS 2.5%9.3CVE-2026-28774Datacast sfx2100 firmware os command injection vulnerabilityAn OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series…EPSS 2.9%9.2CVE-2026-28777Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attac…EPSS 0.63%9.2CVE-2026-29120Datacast sfx2100 firmware hard-coded credentials vulnerabilityThe /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Rece…EPSS 0.16%8.8CVE-2026-29119Datacast sfx2100 firmware hard-coded credentials vulnerabilityInternational Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admi…EPSS 0.63%8.6CVE-2026-29128Datacast sfx2100 firmware insufficiently protected credentials vulnerabilityIDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) th…EPSS 0.29%8.6CVE-2026-29123Datacast sfx2100 firmware improper privilege management vulnerabilityA SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially pre…EPSS 0.13%

Source: NIST National Vulnerability Database (record CVE-2026-29127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.