CVE-2026-29119

Severity CVSS v4.0:
HIGH
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
04/03/2026
Last modified:
04/03/2026

Description

International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via the Telnet service, leading to potential system compromise.

References to Advisories, Solutions, and Tools