CVE-2026-29125: IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-writable `/etc/resolv.conf`
IDC SFX2100 Satalite Recievers set the /etc/resolv.conf file to be world-writable by any local user, allowing DNS resolver tampering that can redirect network communications, facilitate man-in-the-middle attacks, and cause denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29125?
CVE-2026-29125 is considered a high severity vulnerability due to its potential for DNS resolver tampering.
How do I fix CVE-2026-29125?
To fix CVE-2026-29125, modify the permissions of the '/etc/resolv.conf' file to restrict write access to authorized users only.
Who is affected by CVE-2026-29125?
CVE-2026-29125 affects all users of the IDC SFX2100 Satellite Receiver that have not secured the '/etc/resolv.conf' file.
What is the primary risk associated with CVE-2026-29125?
The primary risk of CVE-2026-29125 is that an unprivileged user can alter DNS settings, potentially redirecting network traffic and compromising data integrity.
Is CVE-2026-29125 an exploit that requires remote access?
No, CVE-2026-29125 does not require remote access as it allows local users to modify the DNS configuration.