Description
A path traversal vulnerability exists in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management portal version 101. An authenticated attacker can manipulate the `file` parameter to traverse directories and enumerate arbitrary files on the underlying filesystem. Due to the insecure perl file path handling function in use, a authenticated actor is able to preform directory traversal, with the backup endpoint confirming a file exists by indicating that a backup operation was successful or when using the path of a non existent file, the returned status is failed.
INFO
Published Date :
2026-03-04T07:02:13.741Z
Last Modified :
2026-03-05T05:58:29.757Z
Source :
Gridware
AFFECTED PRODUCTS
The following products are affected by CVE-2026-28769 vulnerability.
| Vendors | Products |
|---|---|
| Datacast |
|
| International Datacasting Corporation (idc) |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-28769.
| URL | Resource |
|---|---|
| https://www.abdulmhsblog.com/posts/sfx2100-vulns/ |
|