An unauthenticated Remote Code Execution (RCE)...
Critical severity
Unreviewed
Published
Mar 4, 2026
to the GitHub Advisory Database
•
Updated Mar 9, 2026
Description
Published by the National Vulnerability Database
Mar 4, 2026
Published to the GitHub Advisory Database
Mar 4, 2026
Last updated
Mar 9, 2026
An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the
privateSNMP community string with read/write access by default. Because the SNMP agent runs as root, an unauthenticated remote attacker can utilizeNET-SNMP-EXTEND-MIBdirectives, abusing the fact that the system runs a vulnerable version of net-snmp pre 5.8, to execute arbitrary operating system commands with root privileges.References