CVE-2026-28776: Datacast SFX2100 Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped into a restricted shell, the attacker can trivially break out to achieve standard shell functionality.

Affected products

  • Datacast SFX2100 Firmware: affected versions not specified

Published 2026-03-04. Last modified 2026-06-17.