International Datacasting Corporation (IDC)
SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/ |
|
History
Wed, 04 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hardcoded and Insecure Credentials for "User" Local Account with SSH Access | Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver |
Wed, 04 Mar 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell. | |
| Title | Hardcoded and Insecure Credentials for "User" Local Account with SSH Access | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gridware
Published:
Updated: 2026-03-04T08:31:22.002Z
Reserved: 2026-03-03T09:59:08.426Z
Link: CVE-2026-28777
No data.
Status : Received
Published: 2026-03-04T08:16:14.113
Modified: 2026-03-04T08:16:14.113
Link: CVE-2026-28777
No data.
OpenCVE Enrichment
No data.
Weaknesses