CVE-2026-28778 HIGH

CVE-2026-28778: Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100

Vendor International Datacasting Corporation (Idc)
Product IDC SFX2100 SuperFlex Satellite Receiver
Weakness CWE-798 · Hardcoded credentials
Published March 4, 2026
Last update March 5, 2026

CVSS base score

7.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H

What the vulnerability does

01Description

International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by `xdstartstop`) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.

Key dates

02Disclosure timeline

March 4, 2026 CVE published
March 5, 2026 Record updated