Vulnerability Description
A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on conditions of the system via execution of the affected SUID binary. This can be via PATH hijacking, symlink abuse or shared object hijacking.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Datacast | Sfx2100 Firmware | - |
| Datacast | Sfx2100 | - |
Related Weaknesses (CWE)
References
- https://www.abdulmhsblog.com/posts/sfx2100-vulns/ExploitThird Party Advisory
FAQ
What is CVE-2026-29123?
CVE-2026-29123 is a vulnerability with a CVSS score of 7.8 (HIGH). A SUID root-owned binary in /home/xd/terminal/XDTerminal in International Data Casting (IDC) SFX2100 on Linux allows a local actor to potentially preform local privilege escalation depending on condit...
How severe is CVE-2026-29123?
CVE-2026-29123 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-29123?
Check the references section above for vendor advisories and patch information. Affected products include: Datacast Sfx2100 Firmware, Datacast Sfx2100.