CVE-2026-28778
Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by `xdstartstop`) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.
| CWE | CWE-798 |
| Vendor | international datacasting corporation (idc) |
| Product | idc sfx2100 superflex satellite receiver |
| Published | Mar 4, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for international datacasting corporation (idc) idc sfx2100 superflex satellite receiver
Be the first to know when new unknown vulnerabilities affecting international datacasting corporation (idc) idc sfx2100 superflex satellite receiver are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
International Datacasting Corporation (IDC) / IDC SFX2100 SuperFlex Satellite Receiver
SFX2100
References
Credits
Abdul Mhanni