Local Privilege Escalation Vulnerability in IDC SFX2100 on Linux
CVE-2026-29123

8.6HIGH

What is CVE-2026-29123?

A local privilege escalation vulnerability exists in the SUID root-owned binary located at /home/xd/terminal/XDTerminal on the IDC SFX2100 running Linux. This flaw could allow a local attacker to escalate their privileges based on specific system conditions through various exploitation techniques including PATH hijacking, symlink abuse, or shared object hijacking. These methods could potentially grant unauthorized access to sensitive system functionalities, compromising the overall security of the affected environment.

Affected Version(s)

SFX2100 Satellite Receiver SFX2100

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.