CVE-2026-29123: Datacast SFX2100 Firmware
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared object hijacking.
Affected products
- Datacast SFX2100 Firmware: affected versions not specified
Published 2026-03-05. Last modified 2026-06-17.