CVE-2026-28778 PUBLISHED

Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100

Assigner: Gridware
Reserved: 03.03.2026 Published: 04.03.2026 Updated: 04.03.2026

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the xd user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the xd user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by xdstartstop) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
CVSS Score: 7.9

Product Status

Vendor International Datacasting Corporation (IDC)
Product IDC SFX2100 SuperFlex Satellite Receiver
Versions Default: unaffected
  • Version SFX2100 is affected

Credits

  • Abdul Mhanni finder

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE

Impacts

  • Unauthorized file system access And Privilege Escalation