PT-2026-23122 · Idc · Sfx2100 Satellite Receiver

Abdul Mhanni

·

Publicado

2026-03-05

·

Atualizado

2026-03-11

·

CVE-2026-29126

CVSS v4.0

8.5

Alta

VetorAV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/AU:N/R:U
Name of the Vulnerable Software and Affected Versions IDC SFX2100 Satellite Receiver (affected versions not specified)
Description A misconfiguration involving incorrect permission assignment of a world-writable file, specifically /etc/udhcpc/default.script, exists. This allows a local, unprivileged attacker to potentially execute arbitrary commands with root privileges. The issue stems from the modification of a root-owned, world-writable BusyBox udhcpc DHCP event script. This script is executed during DHCP lease events – obtaining, renewing, or losing a lease – leading to potential local privilege escalation and persistence.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Incorrect Authorization

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-29126

Produtos afetados

Sfx2100 Satellite Receiver