PT-2026-23100 · International Datacasting · Idc Sfx2100
Abdul Mhanni
·
Published
2026-03-05
·
Updated
2026-03-11
·
CVE-2026-29123
CVSS v4.0
8.6
High
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
International Data Casting (IDC) SFX2100 (affected versions not specified)
Description
A SUID root-owned binary located in
/home/xd/terminal/XDTerminal allows a local actor to potentially perform local privilege escalation depending on system conditions. Exploitation can occur through PATH hijacking, symlink abuse, or shared object hijacking. The vulnerability involves the execution of the affected SUID binary.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Idc Sfx2100