datacast records
20 published records for vendor datacast.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-798 Use of Hard-coded Credentials5
- CWE-269 Improper Privilege Management5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-732 Incorrect Permission Assignment for Critical Resource2
- CWE-91 XML Injection (aka Blind XPath Injection)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-28775No exploit | Unauthenticated RCE via SNMP Default Writable Community Stringdatacast · sfx2100 firmware · CWE-1188 | Critical10.0 | — | 1.1% | Mar 4, 2026 |
38Monitor | CVE-2026-28774No exploit | Authenticated OS Command Injection via Traceroute Utility leads to Root RCEdatacast · sfx2100 firmware · CWE-78 | Critical9.3 | — | 2.9% | Mar 4, 2026 |
38Monitor | CVE-2026-28773No exploit | Authenticated OS Command Injection via Ping Utility Leading to RCE as Rootdatacast · sfx2100 firmware · CWE-78 | Critical9.3 | — | 2.5% | Mar 4, 2026 |
36Monitor | CVE-2026-28777No exploit | Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiverdatacast · sfx2100 firmware · CWE-798 | Critical9.2 | — | 0.6% | Mar 4, 2026 |
36Monitor | CVE-2026-29120No exploit | Insecure, Hardcoded Root Password Stored in Anaconda Configuration File On IDC SFX2100 Satellite Receiverdatacast · sfx2100 firmware · CWE-798 | Critical9.2 | — | 0.2% | Mar 4, 2026 |
36Monitor | CVE-2026-29127No exploit | Incorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100datacast · sfx2100 firmware · CWE-269 | Critical9.2 | — | 0.1% | Mar 4, 2026 |
35Monitor | CVE-2026-29119No exploit | Hardcoded and Insecure Credentials for "Admin" Account providing Telnet Access on IDC SFX2100 Satellite Receiverdatacast · sfx2100 firmware · CWE-798 | High8.8 | — | 0.6% | Mar 4, 2026 |
34Monitor | CVE-2026-29128No exploit | IDC SFX2100 Satellite Receiver bgpd/ospfd/ripd/zebra Config Credential Disclosure via World-Readable Filesdatacast · sfx2100 firmware · CWE-522 | High8.6 | — | 0.3% | Mar 5, 2026 |
34Monitor | CVE-2026-29126No exploit | World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads To Potential LPEdatacast · sfx2100 firmware · CWE-732 | High8.5 | — | 0.2% | Mar 4, 2026 |
34Monitor | CVE-2026-29123No exploit | Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privilege Escalationdatacast · sfx2100 firmware · CWE-269 | High8.6 | — | 0.1% | Mar 4, 2026 |
34Monitor | CVE-2026-29124No exploit | Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local Privilege Escalationdatacast · sfx2100 firmware · CWE-269 | High8.6 | — | 0.1% | Mar 4, 2026 |
33Monitor | CVE-2026-29121No exploit | `/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEdatacast · sfx2100 firmware · CWE-269 | High8.3 | — | 0.2% | Mar 4, 2026 |
33Monitor | CVE-2026-29122No exploit | `/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPEdatacast · sfx2100 firmware · CWE-269 | High8.3 | — | 0.1% | Mar 4, 2026 |
31Monitor | CVE-2026-28778No exploit | Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100datacast · sfx2100 firmware · CWE-798 | High7.9 | — | 0.8% | Mar 4, 2026 |
31Monitor | CVE-2026-28776No exploit | Hardcoded and Insecure Credentials for "monitor" account with SSH Access On IDC SFX2100 Satellite Receiverdatacast · sfx2100 firmware · CWE-798 | High7.8 | — | 0.6% | Mar 4, 2026 |
28Monitor | CVE-2026-29125No exploit | IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-writable `/etc/resolv.conf`datacast · sfx2100 firmware · CWE-732 | High7.1 | — | 0.1% | Mar 4, 2026 |
21Monitor | CVE-2026-28769No exploit | LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumeration On IDC Satellite Receiver Web Management Interface Version 101datacast · sfx2100 firmware · CWE-22 | Medium5.3 | — | 0.8% | Mar 4, 2026 |
21Monitor | CVE-2026-28770No exploit | XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interface Version 101datacast · sfx2100 firmware · CWE-91 | Medium5.3 | — | 0.5% | Mar 4, 2026 |
20Monitor | CVE-2026-28771No exploit | Reflected XSS In /index.cgi Endpoint On IDC Satellite Receiver Web Management Interface Version 101datacast · sfx2100 firmware · CWE-79 | Medium5.1 | — | 0.3% | Mar 4, 2026 |
20Monitor | CVE-2026-28772No exploit | Reflected XSS in IDC_Logging Index endpointdatacast · sfx2100 firmware · CWE-79 | Medium5.1 | — | 0.3% | Mar 4, 2026 |
- CVE-2026-2877540Plan
Unauthenticated RCE via SNMP Default Writable Community String
CriticalCVSS 10.0No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877438Monitor
Authenticated OS Command Injection via Traceroute Utility leads to Root RCE
CriticalCVSS 9.3No exploitEPSS 3%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877338Monitor
Authenticated OS Command Injection via Ping Utility Leading to RCE as Root
CriticalCVSS 9.3No exploitEPSS 2%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877736Monitor
Hardcoded and Insecure Credentials for "User" Local Account with SSH Access On IDC SFX2100 Satellite Receiver
CriticalCVSS 9.2No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912036Monitor
Insecure, Hardcoded Root Password Stored in Anaconda Configuration File On IDC SFX2100 Satellite Receiver
CriticalCVSS 9.2No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912736Monitor
Incorrect Permission Assignment(777) on `monitor` Users Home Directory Containing SUID Root Binaries in IDC SFX2100
CriticalCVSS 9.2No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2911935Monitor
Hardcoded and Insecure Credentials for "Admin" Account providing Telnet Access on IDC SFX2100 Satellite Receiver
HighCVSS 8.8No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912834Monitor
IDC SFX2100 Satellite Receiver bgpd/ospfd/ripd/zebra Config Credential Disclosure via World-Readable Files
HighCVSS 8.6No exploitEPSS 0%datacast · sfx2100 firmwareMar 5, 2026
- CVE-2026-2912634Monitor
World-Writable, Root Owned/Run `/etc/udhcpc/default.script` in IDC SFX2100 Satellite Receiver Leads To Potential LPE
HighCVSS 8.5No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912334Monitor
Multiple SUID Root Binaries in `xd` User Home Directory Leading to Potential Local Privilege Escalation
HighCVSS 8.6No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912434Monitor
Multiple SUID Root Binaries in `monitor` User Home Directory Leading to Potential Local Privilege Escalation
HighCVSS 8.6No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912133Monitor
`/sbin/ip` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE
HighCVSS 8.3No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912233Monitor
`/bin/date` Binary given SETUID Permissions on IDC SFX2100 Leading to Potential LPE
HighCVSS 8.3No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877831Monitor
Hardcoded FTP Credentials and LPE(via Insecure Permissions) for `xd` Local Account on IDC SFX2100
HighCVSS 7.9No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877631Monitor
Hardcoded and Insecure Credentials for "monitor" account with SSH Access On IDC SFX2100 Satellite Receiver
HighCVSS 7.8No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2912528Monitor
IDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-writable `/etc/resolv.conf`
HighCVSS 7.1No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2876921Monitor
LFI in /IDC_Logging/checkifdone.cgi, "file" parameter Allowing for File Existence Enumeration On IDC Satellite Receiver Web Management Interface Version 101
MediumCVSS 5.3No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877021Monitor
XML injection In /IDC_Logging/checkifdone.cgi Endpoint On IDC SFX Web Management Interface Version 101
MediumCVSS 5.3No exploitEPSS 1%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877120Monitor
Reflected XSS In /index.cgi Endpoint On IDC Satellite Receiver Web Management Interface Version 101
MediumCVSS 5.1No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026
- CVE-2026-2877220Monitor
Reflected XSS in IDC_Logging Index endpoint
MediumCVSS 5.1No exploitEPSS 0%datacast · sfx2100 firmwareMar 4, 2026