OS Command Injection Vulnerability in IDC SFX Series SuperFlex SatelliteReceiver
CVE-2026-28773
9.3CRITICAL
Key Information:
- Vendor
- CVE Published:
- 4 March 2026
What is CVE-2026-28773?
The web management interface of the IDC SFX Series SuperFlex SatelliteReceiver contains a vulnerability that allows an authenticated attacker to exploit the application via incorrect parsing of the IPaddr parameter. By leveraging alternative shell metacharacters, an attacker can circumvent server-side security measures and execute arbitrary shell commands with root privileges, posing a significant risk to unauthorized access and system integrity.
Affected Version(s)
SFX Series SuperFlex SatelliteReceiver Web Management Interface 101
