Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Datacast

First CVE: Mar 4, 2026Active for: 1 yearTotal CVEs: 20
47.2
VTI Score
High

Datacast's vulnerability profile concentrates in a single firmware-controlled appliance line, the SFX2100, which despite modest product breadth occupies a prominent position in the landscape. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes endemic to embedded network devices: hard-coded credentials, improper privilege management, OS command injection, and cross-site scripting, reflecting the authentication and input-handling demands of remotely managed appliances. The firmware-centric nature of the product means that remediation often requires coordinated device updates across potentially distributed deployments, making the exposure particularly consequential for operators managing these systems. Defenders should prioritize inventory and access controls for SFX2100 appliances and treat critical disclosures from this vendor as urgent; current severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
10.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Datacast over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 4, 2026
4 months ago
Most Recent CVE
Mar 5, 2026
141 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-28775CRITICAL
An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The d
Mar 4, 20269.833NONO
CVE-2026-29128CRITICAL
IDC SFX2100 Satellite Receiver firmware ships with multiple daemon configuration files for routing components (e.g., zebra, bgpd, ospfd, and ripd) that are owned by root but world-
Mar 5, 202610.031NONO
CVE-2026-28773HIGH
The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Management Interface version
Mar 4, 20268.830NONO
CVE-2026-28770HIGH
Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web ma
Mar 4, 20268.829NONO
CVE-2026-28778CRITICAL
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauth
Mar 4, 20269.828NONO
CVE-2026-29119CRITICAL
International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenti
Mar 4, 20269.827NONO
CVE-2026-28777CRITICAL
International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain
Mar 4, 20269.827NONO
CVE-2026-28776CRITICAL
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can u
Mar 4, 20269.827NONO
CVE-2026-29127HIGH
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting
Mar 5, 20267.826NONO
CVE-2026-28774HIGH
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver We
Mar 4, 20268.826NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
25%
45%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local8 (40.0%)
Network12 (60.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None18 (90.0%)
Unknown0 (0.0%)
Required2 (10.0%)
Privileges Required
Low12 (60.0%)
High0 (0.0%)
None8 (40.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Datacast.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Datacast — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Datacast's Products

View all 1 CNAs →

Top CWEs