Home

Description

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

PUBLISHED Reserved 2026-03-04 | Published 2026-03-04 | Updated 2026-03-04 | Assigner Gridware




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L

Problem types

CWE-798: Use of Hard-coded Credentials

Product status

Default status
unaffected

SFX2100
affected

Credits

Abdul Mhanni finder

References

www.abdulmhsblog.com/posts/spfx-vulnrabilities/

cve.org (CVE-2026-29119)

nvd.nist.gov (CVE-2026-29119)

Download JSON