
CVE-2026-28775 — IDC SFX Series SuperFlex SatelliteReceiver ships with a writable “private” SNMP community and vulnerable net-snmp, letting unauthenticated attackers abuse NET-SNMP-EXTEND-MIB for root-level RCE over SNMP (CVSS 10.0, Critical). Treat broadcast uplinks as high-value OT: lock down SNMP or segment urgently. Source: https://www.cve.org/CVERecord?id=CVE-2026-28775
Post summary
CVE‑2026‑28775 exposes a writable SNMP community in the IDC SFX Series SuperFlex SatelliteReceiver, allowing unauthenticated attackers to achieve root‑level RCE via NET‑SNMP‑EXTEND‑MIB; immediate mitigation is to lock down or segment SNMP traffic.





