Home

Description

IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service.

PUBLISHED Reserved 2026-03-04 | Published 2026-03-05 | Updated 2026-03-05 | Assigner Gridware




HIGH: 7.1CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H

Problem types

CWE-732 Incorrect Permission Assignment for Critical Resource

Product status

Default status
affected

SFX2100
affected

Credits

Abdul Mhanni finder

References

www.abdulmhsblog.com/posts/sfx2100-vulns/

cve.org (CVE-2026-29125)

nvd.nist.gov (CVE-2026-29125)

Download JSON