CVE-2026-29127Disclosure(datacast / sfx2100)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged processes and binaries residing within the affected directory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sfx2100
  • sfx2100_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sfx2100sfx2100_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-08: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-08: 103-0503-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure2
2026-03-081
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29127 Local Privilege Escalation in IDC SFX2100 Satellite Receiver via Permissive File System Permissions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29127

    Post summary

    A new CVE-2026-29127 has been disclosed, describing a local privilege escalation vulnerability in the IDC SFX2100 satellite receiver caused by permissive file system permissions. No PoC, exploit, patch information, or reports of active exploitation are provided.

    1000070
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29127 The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0… https://www.cve.org/CVERecord?id=CVE-2026-29127

    Post summary

    The excerpt announces the discovery that the IDC SFX2100 Satellite Receiver assigns overly permissive file‑system permissions, representing a basic disclosure of a configuration vulnerability.

    00000211
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29127 - Incorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100 Intel Report: https://ift.tt/fUnRJYM

    Post summary

    The alert announces CVE-2026-29127, detailing a permission misconfiguration affecting SUID root binaries in a monitor user's home directory, with an Intel report link but no mention of exploits, patches, or active exploitation.

    0000041
    343 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdatacastsfx2100---
OSdatacastsfx2100_firmware---

Explore more