Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| International Datacasting Corporation (IDC) | SFX Series SuperFlex SatelliteReceiver Web Management Interface | 101 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28770 | XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interface | |
| CVE-2026-28769 | LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumerat | |
| CVE-2026-28772 | Reflected XSS in IDC_Logging Index endpoint | |
| CVE-2026-28774 | Authenticated OS Command Injection via Traceroute Utility leads to Root RCE | |
| CVE-2026-28771 | Reflected XSS In /index.cgi Endpoint On IDC Satellite Receiver Web Management Interface Ve | |
| CVE-2026-28775 | Unauthenticated RCE via SNMP Default Writable Community String | |
| CVE-2026-29119 | Hardcoded and Insecure Credentials for "Admin" Account providing Telnet Access on IDC SFX2 | |
| CVE-2026-28777 | Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 | |
| CVE-2026-28776 | Hardcoded and Insecure Credentials for "monitor" account with SSH Access On IDC SFX2100 Sa | |
| CVE-2026-28778 | Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC |
No comments yet