Local Privilege Escalation in IDC SFX2100 Satellite Receiver
CVE-2026-29126

8.5HIGH

What is CVE-2026-29126?

A security flaw in the International Data Casting SFX2100 Satellite Receiver involves incorrect permission settings on the /etc/udhcpc/default.script file. This world-writable file can be altered by local unprivileged attackers, enabling them to execute arbitrary commands with elevated root privileges. This occurs during DHCP events—when leases are obtained, renewed, or lost—by executing a compromised BusyBox udhcpc DHCP event script. This vulnerability poses a significant risk of unauthorized access and potential persistence within the system.

Affected Version(s)

SFX2100 Satellite Receiver SFX2100

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.