Local Privilege Escalation Vulnerability in IDC SFX2100 Satellite Receiver
CVE-2026-29127

9.2CRITICAL

What is CVE-2026-29127?

The IDC SFX2100 Satellite Receiver is vulnerable due to its configuration of overly permissive file system permissions on the monitor user's home directory, set to 0777. This provision allows read, write, and execute access to all local users on the system. Under certain conditions, this vulnerability could enable local privilege escalation, particularly in environments where highly privileged processes and binaries reside within the compromised directory. This creates an opportunity for unauthorized users to exploit the system and gain elevated access rights, potentially compromising sensitive data and system integrity.

Affected Version(s)

SFX2100 Satellite Receiver SFX2100

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdul Mhanni
.