Home

Description

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

PUBLISHED Reserved 2026-03-03 | Published 2026-03-04 | Updated 2026-03-05 | Assigner Gridware




CRITICAL: 10.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-1188: Insecure Default Initialization of Resource

Product status

Default status
unaffected

SFX2100
affected

Credits

Abdul Mhanni finder

References

www.abdulmhsblog.com/posts/sfx2100-vulns/

cve.org (CVE-2026-28775)

nvd.nist.gov (CVE-2026-28775)

Download JSON