CVE-2026-28773General(datacast / sfx2100)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite  Receiver Web Management Interface version 101 is vulnerable to OS Command Injection. The application insecurely parses the `IPaddr` parameter. An authenticated attacker can bypass server-side semicolon exclusion checks by using alternate shell metacharacters (such as the pipe `|` operator) to append and execute arbitrary shell commands with root privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sfx2100
  • sfx2100_firmware

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
sfx2100sfx2100_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-04: 3Mentions · 2026-03-05: 1Technical Details · 2026-03-04: 103-0403-05
Signal classification2 categories
General
375.0%
Disclosure
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-043
Disclosure1General2
2026-03-051
General1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28773 OS Command Injection in IDC SFX Series SuperFlex Satellit... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28773 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE‑2026‑28773 as an OS Command Injection in IDC SFX Series SuperFlex Satellit and links to a vulnerability detail page, but does not discuss exploitation, patches, or provide a PoC.

    0001056
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28773 The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interf… https://www.cve.org/CVERecord?id=CVE-2026-28773

    Post summary

    The text references CVE‑2026‑28773 for a web‑based Ping utility in IDC SFX Series SuperFlex SatelliteReceiver Web Management Interface but provides no additional details or actionable information.

    00010345
    56.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28773 📊 Severity: 9.3 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28773 #CVE-2026-28773 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/Cn1xoihEwX

    Post summary

    The tweet announces a new CVE (CVE-2026-28773) with a high severity rating but provides no further technical details, patches, or evidence of exploitation.

    0000043
    65 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-28773 The web-based Ping diagnostic utility (/IDC_Ping/main.cgi) in International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interf… https://www.cve.org/CVERecord?id=CVE-2026-28773 ----- Traducción: CVE-2026-28773 La … http://infoflow.cloud`

    Post summary

    The post references CVE-2026-28773 and links to its CVE record, but offers no additional details on exploitation, patches, or technical specifics.

    0000021
    55 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdatacastsfx2100---
OSdatacastsfx2100_firmware---

Explore more