CVE-2026-28774
Severity CVSS v4.0:
CRITICAL
Type:
CWE-78
OS Command Injections
Publication date:
04/03/2026
Last modified:
09/03/2026
Description
An OS Command Injection vulnerability exists in the web-based Traceroute diagnostic utility of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101. An authenticated attacker can inject arbitrary shell metacharacters (such as the pipe `|` operator) into the flags parameter, leading to the execution of arbitrary operating system commands with root privileges.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



