A security researcher publicly disclosed 20+ vulnerabilities in the International Data Casting (IDC) SFX2100 satellite receiver, a device reported as deployed across U.S. Department of Defense, European Space Agency, and other critical infrastructure environments, after the vendor allegedly failed to respond to repeated disclosure attempts over several months. Reported issues span common embedded-device failure modes including hardcoded credentials, unauthenticated remote code execution, OS command injection, path traversal, and overly permissive filesystem configurations, with CVEs assigned across CVE-2026-28769 through CVE-2026-29128. One highlighted high-impact issue, CVE-2026-28775, reportedly enables unauthenticated command execution as root by abusing SNMP management functionality combined with a default read-write community string of private.
Additional detail on the credential exposure risk is captured in CVE-2026-29128, which describes world-readable routing daemon configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) that are root-owned but readable by all users and contain plaintext/hardcoded passwords (including privileged “enable” credentials). This condition can enable credential reuse and lateral movement, potentially helping an attacker establish or deepen access within networks where the SFX2100 is deployed, and it compounds other reported weaknesses such as undocumented default accounts (e.g., admin, monitor, user, xd) allegedly sharing a weak password (12345).

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Coverage of the disclosure stated that IDC had not released a public advisory, statement, or patches for the SFX2100 vulnerabilities as of publication. The researcher recommended that affected organizations inventory and isolate exposed devices until fixes become available.
After receiving no vendor response, the researcher publicly disclosed more than 20 security flaws in IDC's SFX2100 satellite receiver. The disclosure highlighted severe risks to deployments used by organizations including the U.S. Department of Defense, the European Space Agency, and other critical infrastructure operators.
Public vulnerability details were released for CVE-2026-29128, describing world-readable routing daemon configuration files on the SFX2100 that expose plaintext passwords, including privileged enable credentials. The disclosure warned the credentials could be reused to access other network systems and potentially help an attacker gain a foothold or escalate privileges.
Twenty vulnerabilities affecting the IDC SFX2100 satellite receiver were assigned CVEs in the range CVE-2026-28769 through CVE-2026-29128. The issues included hardcoded credentials, unauthenticated remote code execution, command injection, path traversal, and weak filesystem permissions.
A penetration tester repeatedly attempted to disclose more than 20 vulnerabilities in IDC's SFX2100 satellite receiver to the vendor over several months, including outreach within a 90-day responsible disclosure period. IDC reportedly did not respond to the disclosure attempts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
thecyberexpress.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.