CVE-2026-29119: Datacast SFX2100 Firmware

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

Affected products

  • Datacast SFX2100 Firmware: affected versions not specified

Published 2026-03-04. Last modified 2026-06-17.