CVE-2026-28775 is an unauthenticated Remote Code Execution (RCE) vulnerability in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceivers. It arises from the default provisioning of the 'private' SNMP community string with read/write access and the SNMP agent running as root on a vulnerable net-snmp version. This allows an unauthenticated remote attacker to execute arbitrary operating system commands with root privileges. Rated as Critical (CVSS 10.0), the vulnerability has a low attack complexity and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. There is currently no public exploit code available, it is not on the KEV catalog, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.