Elevated Privileges in International Data Casting SFX2100 Satellite Receiver
CVE-2026-29122

8.3HIGH

What is CVE-2026-29122?

The International Data Casting SFX2100 satellite receiver includes a vulnerable installation of the /bin/date utility with the setuid bit enabled. This security misconfiguration allows any local user to execute the binary with elevated privileges, potentially enabling them to perform unauthorized file read operations as the root user. This includes access to sensitive files such as the /etc/shadow file and other critical configuration files that contain sensitive information.

Affected Version(s)

SFX2100 Satellite Receiver SFX2100

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.