Remote Code Execution Vulnerability in IDC SFX Series SuperFlex SatelliteReceiver
CVE-2026-28775
Key Information:
- Vendor
- CVE Published:
- 4 March 2026
Badges
What is CVE-2026-28775?
An unauthenticated Remote Code Execution vulnerability in the SNMP service of International Datacasting Corporation's SFX Series SuperFlex SatelliteReceiver allows attackers to exploit insecure provisioning of the 'private' SNMP community string, which grants read/write access by default. This security oversight enables remote attackers to execute arbitrary commands with root privileges due to the underlying net-snmp service running in a vulnerable state. The issue arises from the utilization of NET-SNMP-EXTEND-MIB directives, particularly in versions prior to 5.8. Organizations utilizing affected devices should promptly apply any available security patches to mitigate risks.
Affected Version(s)
SFX2100 Series SuperFlex SatelliteReceiver SFX2100
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
