Privilege Escalation Vulnerability in IDC SFX2100 Satellite Receiver
CVE-2026-29121

8.3HIGH

What is CVE-2026-29121?

The IDC SFX2100 satellite receiver is vulnerable due to the inclusion of the /sbin/ip utility with the setuid bit enabled. This configuration allows any local user to execute the binary with elevated privileges, enabling them to perform privileged file reads as the root user. Such access can lead to further exploitation and unauthorized actions within the local file system.

Affected Version(s)

SFX2100 Satellite Receiver SFX2100

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.