Datacast's vulnerability profile concentrates in a single firmware-controlled appliance line, the SFX2100, which despite modest product breadth occupies a prominent position in the landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes endemic to embedded network devices: hard-coded credentials, improper privilege management, OS command injection, and cross-site scripting, reflecting the authentication and input-handling demands of remotely managed appliances. The firmware-centric nature of the product means that remediation often requires coordinated device updates across potentially distributed deployments, making the exposure particularly consequential for operators managing these systems. Defenders should prioritize inventory and access controls for SFX2100 appliances and treat critical disclosures from this vendor as urgent; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Datacast over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28775CRITICAL An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The d | Mar 4, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-29128CRITICAL IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world- | Mar 5, 2026 | 10.0 | 31 | NO | NO |
CVE-2026-28773HIGH The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version | Mar 4, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-28770HIGH Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web ma | Mar 4, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-28778CRITICAL International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauth | Mar 4, 2026 | 9.8 | 28 | NO | NO |
CVE-2026-29119CRITICAL International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenti | Mar 4, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-28777CRITICAL International Datacasting Corporation (IDC)
SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain | Mar 4, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-28776CRITICAL International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can u | Mar 4, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-29127HIGH The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting | Mar 5, 2026 | 7.8 | 26 | NO | NO |
CVE-2026-28774HIGH An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver We | Mar 4, 2026 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Datacast.
Media articles that mention a CVE ID that affects a product developed by Datacast — matched by CVE ID, not by vendor name.