CVE-2026-28775Disclosure(datacast / sfx2100)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch datacast sfx2100 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilize `NET-SNMP-EXTEND-MIB` directives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sfx2100
  • sfx2100_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-03-04); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
sfx2100sfx2100_firmware

1 version affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Mentions · 2026-04-24: 1Active Exploitation · 2026-03-04: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-03-04: 3Technical Details · 2026-04-24: 103-0403-0504-24
Signal classification2 categories
Disclosure
583.3%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-044
Active Exploitation1Disclosure3
2026-03-051
Disclosure1
2026-04-241
Disclosure1
Full discourse6 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2026-28775 — IDC SFX Series SuperFlex SatelliteReceiver ships with a writable “private” SNMP community and vulnerable net-snmp, letting unauthenticated attackers abuse NET-SNMP-EXTEND-MIB for root-level RCE over SNMP (CVSS 10.0, Critical). Treat broadcast uplinks as high-value OT: lock down SNMP or segment urgently. Source: https://www.cve.org/CVERecord?id=CVE-2026-28775

    Post summary

    CVE‑2026‑28775 exposes a writable SNMP community in the IDC SFX Series SuperFlex SatelliteReceiver, allowing unauthenticated attackers to achieve root‑level RCE via NET‑SNMP‑EXTEND‑MIB; immediate mitigation is to lock down or segment SNMP traffic.

    0001088
    1.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-28775 📊 Severity: 10.0 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28775 #CVE-2026-28775 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/ijiR6GsAfi

    Post summary

    The tweet announces a new CVE‑2026‑28775 with a top severity score of 10.0, affecting multiple unspecified products, without providing PoC, exploit, or patch information.

    0000033
    65 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting International Datacasting Corporation SFX2100 SuperFlex SatelliteReceiver (CVE-2026-28775) https://vuldb.com/?ctiid.348691

    Post summary

    The post indicates that CVE-2026-28775 is currently being actively exploited, but it lacks detailed technical or patch information.

    0000065
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28775 Unauthenticated Root RCE in IDC SFX Series Satellite Receiver via SNMP Extend MIB https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28775

    Post summary

    The text announces a newly disclosed unauthenticated root RCE in IDC SFX Series Satellite Receivers via SNMP Extend MIB, with technical details but no PoC, patch, or active exploitation indicated.

    0000055
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-28775 An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteR… https://www.cve.org/CVERecord?id=CVE-2026-28775 ----- Traducción: CVE-2026-28775 Exi… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-28775, an unauthenticated RCE in the SNMP service of IDC SFX Series, and links to the official CVE record.

    0000031
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28775 An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteR… https://www.cve.org/CVERecord?id=CVE-2026-28775

    Post summary

    The CVE-2026-28775 describes an unauthenticated RCE in the SNMP service of IDC SFX Series SuperFlex SatelliteR, but no PoC, exploit, patch, or active exploitation details are provided.

    00000377
    56.6K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdatacastsfx2100---
OSdatacastsfx2100_firmware---

Explore more