International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
History

Wed, 04 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared International Datacasting Corporation (idc)
International Datacasting Corporation (idc) sfx2100 Satellite Receiver
Vendors & Products International Datacasting Corporation (idc)
International Datacasting Corporation (idc) sfx2100 Satellite Receiver

Wed, 04 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Title Hardcoded and Insecure Credentials for "User" Local Account with SSH Access Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver

Wed, 04 Mar 2026 08:00:00 +0000

Type Values Removed Values Added
Description International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Title Hardcoded and Insecure Credentials for "User" Local Account with SSH Access
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2026-03-04T15:20:16.624Z

Reserved: 2026-03-03T09:59:08.426Z

Link: CVE-2026-28777

cve-icon Vulnrichment

Updated: 2026-03-04T15:19:59.511Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T08:16:14.113

Modified: 2026-03-04T18:08:05.730

Link: CVE-2026-28777

cve-icon Redhat

No data.