CVE-2026-29127: Incorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100
The IDC SFX2100 Satellite Receiver sets overly permissive file system permissions on the monitor user's home directory. The directory is configured with permissions 0777, granting read, write, and execute access to all local users on the system, which may cause local privilege escalation depending on conditions of the system due to the presence of highly privileged processes and binaries residing within the affected directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29127?
CVE-2026-29127 is classified as a high severity vulnerability due to the improper permission assignment leading to potential exploitation.
How do I fix CVE-2026-29127?
To resolve CVE-2026-29127, change the permissions of the monitor user's home directory from 0777 to a more restrictive setting like 0755.
What are the risks associated with CVE-2026-29127?
The risks of CVE-2026-29127 include unauthorized access to sensitive files and the potential execution of malicious code by unprivileged users.
Which systems are affected by CVE-2026-29127?
CVE-2026-29127 affects the IDC SFX2100 Satellite Receiver that has improperly configured file system permissions.
Who is impacted by CVE-2026-29127?
Users and administrators of the IDC SFX2100 Satellite Receiver are impacted by CVE-2026-29127 due to the security risks from the incorrect permissions.