A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101. The application fails to adequately sanitize user-supplied input provided via the `cat` parameter before reflecting it in the HTTP response, allowing a remote attacker to execute arbitrary HTML or JavaScript in the victim's browser context.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.abdulmhsblog.com/posts/spfx-vulnrabilities/ |
|
History
Wed, 04 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS In /index.cgi Endpoint On IDC Satellite Receiver Web Management Interface Version 101 |
Wed, 04 Mar 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web Management Interface version 101. The application fails to adequately sanitize user-supplied input provided via the `cat` parameter before reflecting it in the HTTP response, allowing a remote attacker to execute arbitrary HTML or JavaScript in the victim's browser context. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Gridware
Published:
Updated: 2026-03-04T08:30:05.071Z
Reserved: 2026-03-03T09:59:08.426Z
Link: CVE-2026-28771
No data.
Status : Received
Published: 2026-03-04T08:16:13.173
Modified: 2026-03-04T08:16:13.173
Link: CVE-2026-28771
No data.
OpenCVE Enrichment
No data.
Weaknesses