CVE Explorer
CVE-2026-29119
International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"SFX2100 Series SuperFlex SatelliteReceiver","vendor":"International Datacasting Corporation (IDC)","versions":[{"status":"affected","version":"SFX2100"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:deb9065403b3c8f5c37845ba7a6af1d133921f16a3a5676667fb4bef667e3176 · sha256:721c9cb735b8d30a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"LOW","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:deb9065403b3c8f5c37845ba7a6af1d133921f16a3a5676667fb4bef667e3176 · sha256:721c9cb735b8d30a… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-798","description":"CWE-798: Use of Hard-coded Credentials","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:deb9065403b3c8f5c37845ba7a6af1d133921f16a3a5676667fb4bef667e3176 · sha256:721c9cb735b8d30a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.abdulmhsblog.com/posts/sfx2100-vulns/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:deb9065403b3c8f5c37845ba7a6af1d133921f16a3a5676667fb4bef667e3176 · sha256:721c9cb735b8d30a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.