PT-2026-22877 · International Datacasting+1 · Sfx Series Superflex Satellitereceiver+1

Abdul Mhanni

·

Published

2026-03-04

·

Updated

2026-04-24

·

CVE-2026-28775

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver versions prior to 5.8
Description An unauthenticated Remote Code Execution (RCE) issue exists in the SNMP service. The system insecurely configures the private SNMP community string with read/write access by default. Because the SNMP agent operates with root privileges, a remote attacker without authentication can leverage NET-SNMP-EXTEND-MIB directives to execute arbitrary operating system commands with root privileges. This is possible due to the system running a version of net-snmp prior to 5.8.
Recommendations Update the net-snmp library to version 5.8 or later. Change the default SNMP community string from private to a strong, unique value. Restrict access to the SNMP service to authorized networks and hosts. Disable the NET-SNMP-EXTEND-MIB if it is not required.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-28775

Affected Products

Sfx Series Superflex Satellitereceiver
Net-Snmp