CVE-2026-29119: Hardcoded and Insecure Credentials for "Admin" Account providing Telnet Access on IDC SFX2100 Satellite Receiver
International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the admin account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29119?
CVE-2026-29119 is considered a high severity vulnerability due to the presence of hardcoded and insecure credentials for the admin account.
How do I fix CVE-2026-29119?
To mitigate CVE-2026-29119, you should update the firmware of the SFX2100 Satellite Receiver to a version that removes the hardcoded credentials.
What systems are affected by CVE-2026-29119?
CVE-2026-29119 specifically affects the International Datacasting Corporation SFX2100 Satellite Receiver.
Can CVE-2026-29119 be exploited remotely?
Yes, CVE-2026-29119 can be exploited remotely as it allows unauthenticated access via Telnet.
What type of attack does CVE-2026-29119 facilitate?
CVE-2026-29119 facilitates unauthorized access and potential control of the device by leveraging hardcoded credentials.