CVE-2026-28778
Severity CVSS v4.0:
HIGH
Type:
CWE-798
Use of Hard-coded Credentials
Publication date:
04/03/2026
Last modified:
17/03/2026
Description
International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write permissions to their home directory where root-executed binaries and symlinks (such as those invoked by `xdstartstop`) are stored, the attacker can overwrite these files or manipulate symlinks to achieve arbitrary code execution as the root user.
Impact
Base Score 4.0
7.90
Severity 4.0
HIGH
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:datacast:sfx2100_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:datacast:sfx2100:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



