CVE-2026-29126: World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads To Potential LPE
Incorrect permission assignment (world-writable file) in /etc/udhcpc/default.script in International Data Casting (IDC) SFX2100 Satellite Receiver allows a local unprivileged attacker to potentially execute arbitrary commands with root privileges (local privilege escalation and persistence) via modification of a root-owned, world-writable BusyBox udhcpc DHCP event script, which is executed when a DHCP lease is obtained, renewed, or lost.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29126?
CVE-2026-29126 has a high severity due to its potential for local privilege escalation.
How do I fix CVE-2026-29126?
To fix CVE-2026-29126, you should change the permissions of the /etc/udhcpc/default.script file to prevent world-writable access.
What type of vulnerability is CVE-2026-29126?
CVE-2026-29126 is a local privilege escalation vulnerability caused by incorrect permission settings.
Who is affected by CVE-2026-29126?
Users of the International Data Casting SFX2100 Satellite Receiver are affected by CVE-2026-29126.
What can an attacker do with CVE-2026-29126?
An attacker can exploit CVE-2026-29126 to gain elevated privileges on the system.