International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
History

Wed, 04 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Title Hardcoded and Insecure Credentials for "User" Local Account with SSH Access Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver

Wed, 04 Mar 2026 08:00:00 +0000

Type Values Removed Values Added
Description International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker can trivially spawn a complete pty to gain an appropriately interactive shell.
Title Hardcoded and Insecure Credentials for "User" Local Account with SSH Access
Weaknesses CWE-798
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2026-03-04T08:31:22.002Z

Reserved: 2026-03-03T09:59:08.426Z

Link: CVE-2026-28777

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-04T08:16:14.113

Modified: 2026-03-04T08:16:14.113

Link: CVE-2026-28777

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.