Description
International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.
Problem types
CWE-798: Use of Hard-coded Credentials
Product status
SFX2100
Credits
Abdul Mhanni
References
www.abdulmhsblog.com/posts/spfx-vulnrabilities/