PT-2026-22871 · International Datacasting · Sfx Series Superflex Satellitereceiver
Abdul Mhanni
·
Published
2026-03-04
·
Updated
2026-03-05
·
CVE-2026-28769
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 101
Description
A path traversal issue exists in the
/IDC Logging/checkifdone.cgi script. An authenticated attacker can manipulate the file parameter to access arbitrary files on the system. This is due to insecure file path handling within the perl script. The vulnerability allows directory traversal, and the system confirms file existence through backup operation status.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sfx Series Superflex Satellitereceiver