Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
embedded-device-vulnerabilitydefault-credential-exposurecritical-infrastructure-threatcredential-access-method

Unpatched IDC SFX2100 Satellite Receiver Vulnerabilities Expose Critical Infrastructure to Remote Compromise

Updated 3mo agoFirst seen Mar 7, 20262 sources

A security researcher publicly disclosed 20+ vulnerabilities in the International Data Casting (IDC) SFX2100 satellite receiver, a device reported as deployed across U.S. Department of Defense, European Space Agency, and other critical infrastructure environments, after the vendor allegedly failed to respond to repeated disclosure attempts over several months. Reported issues span common embedded-device failure modes including hardcoded credentials, unauthenticated remote code execution, OS command injection, path traversal, and overly permissive filesystem configurations, with CVEs assigned across CVE-2026-28769 through CVE-2026-29128. One highlighted high-impact issue, CVE-2026-28775, reportedly enables unauthenticated command execution as root by abusing SNMP management functionality combined with a default read-write community string of private.

Additional detail on the credential exposure risk is captured in CVE-2026-29128, which describes world-readable routing daemon configuration files (e.g., zebra.conf, bgpd.conf, ospfd.conf, ripd.conf) that are root-owned but readable by all users and contain plaintext/hardcoded passwords (including privileged “enable” credentials). This condition can enable credential reuse and lateral movement, potentially helping an attacker establish or deepen access within networks where the SFX2100 is deployed, and it compounds other reported weaknesses such as undocumented default accounts (e.g., admin, monitor, user, xd) allegedly sharing a weak password (12345).

Share:
Unpatched IDC SFX2100 Satellite Receiver Vulnerabilities Expose Critical Infrastructure to Remote Compromise
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 6, 20264mo ago

Public reporting notes IDC had issued no statement or patches

Coverage of the disclosure stated that IDC had not released a public advisory, statement, or patches for the SFX2100 vulnerabilities as of publication. The researcher recommended that affected organizations inventory and isolate exposed devices until fixes become available.

Researcher publicly discloses 20+ unpatched SFX2100 vulnerabilities

After receiving no vendor response, the researcher publicly disclosed more than 20 security flaws in IDC's SFX2100 satellite receiver. The disclosure highlighted severe risks to deployments used by organizations including the U.S. Department of Defense, the European Space Agency, and other critical infrastructure operators.

Mar 5, 20264mo ago

CVE-2026-29128 details published for world-readable credential files

Public vulnerability details were released for CVE-2026-29128, describing world-readable routing daemon configuration files on the SFX2100 that expose plaintext passwords, including privileged enable credentials. The disclosure warned the credentials could be reused to access other network systems and potentially help an attacker gain a foothold or escalate privileges.

Twenty SFX2100 vulnerabilities receive CVE assignments

Twenty vulnerabilities affecting the IDC SFX2100 satellite receiver were assigned CVEs in the range CVE-2026-28769 through CVE-2026-29128. The issues included hardcoded credentials, unauthenticated remote code execution, command injection, path traversal, and weak filesystem permissions.

Dec 6, 20257mo ago

Researcher reports SFX2100 flaws to IDC during 90-day disclosure window

A penetration tester repeatedly attempted to disclose more than 20 vulnerabilities in IDC's SFX2100 satellite receiver to the vendor over several months, including outreach within a 90-day responsible disclosure period. IDC reportedly did not respond to the disclosure attempts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

2 LINKEDOpen in app
Organizations
2 linked
International Data CorporationIDC
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.