PT-2026-23122 · Idc · Sfx2100 Satellite Receiver
Abdul Mhanni
·
Publicado
2026-03-05
·
Atualizado
2026-03-11
·
CVE-2026-29126
CVSS v4.0
8.5
Alta
| Vetor | AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:H/SI:H/SA:H/AU:N/R:U |
Name of the Vulnerable Software and Affected Versions
IDC SFX2100 Satellite Receiver (affected versions not specified)
Description
A misconfiguration involving incorrect permission assignment of a world-writable file, specifically
/etc/udhcpc/default.script, exists. This allows a local, unprivileged attacker to potentially execute arbitrary commands with root privileges. The issue stems from the modification of a root-owned, world-writable BusyBox udhcpc DHCP event script. This script is executed during DHCP lease events – obtaining, renewing, or losing a lease – leading to potential local privilege escalation and persistence.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Incorrect Authorization
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sfx2100 Satellite Receiver