๐Ÿ” CVE Alert

CVE-2026-29120

UNKNOWN 0.0

Insecure, Hardcoded Root Password Stored in Anaconda Configuration File On IDC SFX2100 Satellite Receiver

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and susceptible to offline dictionary attacks using the rockyou.txt wordlist. Because direct root SSH login is disabled, an attacker must first obtain low-privileged access to the system (e.g., via other vulnerabilities) to be able to log in as the root user. The password is hardcoded and so allows for an actor with local access on effected versions to escalate to root

CWE CWE-798
Vendor international datacasting corporation
Product idc sfx2100 superflex satellite receiver
Published Mar 4, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for international datacasting corporation idc sfx2100 superflex satellite receiver

Be the first to know when new unknown vulnerabilities affecting international datacasting corporation idc sfx2100 superflex satellite receiver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

International Datacasting Corporation / IDC SFX2100 SuperFlex Satellite Receiver
SFX2100

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
abdulmhsblog.com: https://www.abdulmhsblog.com/posts/sfx2100-vulns/

Credits

Abdul Mhanni