Datacast

Sfx2100 Firmware

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 05.03.2026 05:12:35
  • Zuletzt bearbeitet 09.03.2026 18:36:42

IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-readable. The configuration files (e.g., zebra.conf, bgpd.conf, ospfd....

Exploit
  • EPSS 0.01%
  • Veröffentlicht 05.03.2026 02:36:12
  • Zuletzt bearbeitet 09.03.2026 18:42:33

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, whic...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.03.2026 01:51:06
  • Zuletzt bearbeitet 11.03.2026 18:34:00

Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (lo...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.03.2026 01:38:18
  • Zuletzt bearbeitet 11.03.2026 18:35:19

IDC SFX2100 Satalite Recievers set the `/etc/resolv.conf` file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.03.2026 01:23:35
  • Zuletzt bearbeitet 11.03.2026 18:35:30

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, wh...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 05.03.2026 01:18:58
  • Zuletzt bearbeitet 11.03.2026 18:35:37

A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected S...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.03.2026 00:53:24
  • Zuletzt bearbeitet 11.03.2026 18:35:46

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/bin/date` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.03.2026 00:48:59
  • Zuletzt bearbeitet 11.03.2026 18:35:55

International Data Casting (IDC) SFX2100 satellite receiver comes with the `/sbin/ip` utility installed with the setuid bit set. This configuration grants elevated privileges to any local user who can execute the binary. A local actor is able to use ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 04.03.2026 08:16:14
  • Zuletzt bearbeitet 17.03.2026 16:55:21

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the sa...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 04.03.2026 08:16:14
  • Zuletzt bearbeitet 17.03.2026 17:08:34

The /root/anaconda-ks.cfg installation configuration file in International Datacasting Corporation (IDC) SFX Series(SFX2100) SuperFlex Satellite Receiver insecurely stores the hardcoded root password hash. The password itself is highly insecure and s...