CVE-2026-28773: Datacast SFX2100 Firmware
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr` parameter. An authenticated attacker can bypass server-side semicolon exclusion checks by using alternate shell metacharacters (such as the pipe `|` operator) to append and execute arbitrary shell commands with root privileges.
Affected products
- Datacast SFX2100 Firmware: affected versions not specified
Published 2026-03-04. Last modified 2026-06-17.