CVE-2026-29124 PUBLISHED

Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local Privilege Escalation

Assigner: Gridware
Reserved: 04.03.2026 Published: 05.03.2026 Updated: 05.03.2026

Multiple SUID root-owned binaries are found in /home/monitor/terminal, /home/monitor/kore-terminal, /home/monitor/IDE-DPack/terminal-dpack, and /home/monitor/IDE-DPack/terminal-dpack2 in International Data Casting (IDC) SFX2100 Satellite Receiver, which may lead to local privlidge escalation from the monitor user to root

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 8.6

Product Status

Vendor International Datacasting Corporation
Product SFX2100 Satellite Receiver
Versions Default: affected
  • Version SFX2100 is affected

Credits

  • Abdul Mhanni finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE

Impacts

  • CAPEC-233 Privilege Escalation