CVE-2026-28775

CVSS

No CVSS.

A

n unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Configurations

No configuration.

History

05 Mar 2026, 06:16

Type Values Removed Values Added
References
  • {'url': 'https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/', 'source': 'b7efe717-a805-47cf-8e9a-921fca0ce0ce'}
  • () https://www.abdulmhsblog.com/posts/sfx2100-vulns/ -

04 Mar 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-04 08:16

Updated : 2026-03-05 06:16


NVD link : CVE-2026-28775

Mitre link : CVE-2026-28775

CVE.ORG link : CVE-2026-28775


JSON object : View

Products Affected

No product.

CWE
CWE-1188

Initialization of a Resource with an Insecure Default