PT-2026-22877 · International Datacasting+1 · Sfx Series Superflex Satellitereceiver+1
Abdul Mhanni
·
Published
2026-03-04
·
Updated
2026-04-24
·
CVE-2026-28775
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver versions prior to 5.8
Description
An unauthenticated Remote Code Execution (RCE) issue exists in the SNMP service. The system insecurely configures the
private SNMP community string with read/write access by default. Because the SNMP agent operates with root privileges, a remote attacker without authentication can leverage NET-SNMP-EXTEND-MIB directives to execute arbitrary operating system commands with root privileges. This is possible due to the system running a version of net-snmp prior to 5.8.Recommendations
Update the net-snmp library to version 5.8 or later.
Change the default SNMP community string from
private to a strong, unique value.
Restrict access to the SNMP service to authorized networks and hosts.
Disable the NET-SNMP-EXTEND-MIB if it is not required.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sfx Series Superflex Satellitereceiver
Net-Snmp