CVE-2026-28775 PUBLISHED

Unauthenticated RCE via SNMP Default Writable Community String

Assigner: Gridware
Reserved: 03.03.2026 Published: 04.03.2026 Updated: 04.03.2026

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the private SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize NET-SNMP-EXTEND-MIB directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 10

Product Status

Vendor International Datacasting Corporation (IDC)
Product SFX2100 Series SuperFlex SatelliteReceiver
Versions Default: unaffected
  • Version SFX2100 is affected

Credits

  • Abdul Mhanni finder

References

Problem Types

  • CWE-1188: Insecure Default Initialization of Resource CWE

Impacts

  • Unauthenticated Remote Code Execution (RCE) as Root