logo

A Satellite Receiver Trusted by Pentagon, ESA Has More Than 20 Security Flaws — and the Maker Never Responded

ID: 2d3a7892-ffa7-52de-86ac-6bac6fe961af

STIX ID: report--2d3a7892-ffa7-52de-86ac-6bac6fe961af

Feed Name: The Cyber Express

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

A researcher found 20+ critical vulnerabilities in IDC's SFX2100 satellite receiver — including unauthenticated root RCE via SNMP (default RW community string), hardcoded accounts with password "12345", web command injection, and an FTP writable path allowing replacement of a root-executing binary — impacting systems used by the U.S. DoD, ESA, and other critical infrastructure; IDC did not respond to disclosures and the flaws are likely present across the product line.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.