A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101 allows a remote attacker to execute arbitrary web scripts or HTML. The vulnerability is triggered by sending a crafted payload through the `submitType` parameter, which is reflected directly into the DOM without proper escaping.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Mar 2026 13:45:00 +0000

Type Values Removed Values Added
Title Reflected XSS in Logging Index endpoint Reflected XSS in IDC_Logging Index endpoint

Wed, 04 Mar 2026 07:30:00 +0000

Type Values Removed Values Added
Description A Reflected Cross-Site Scripting (XSS) vulnerability in the /IDC_Logging/index.cgi endpoint of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver Web Management Interface version 101 allows a remote attacker to execute arbitrary web scripts or HTML. The vulnerability is triggered by sending a crafted payload through the `submitType` parameter, which is reflected directly into the DOM without proper escaping.
Title Reflected XSS in Logging Index endpoint
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Gridware

Published:

Updated: 2026-03-04T13:26:03.774Z

Reserved: 2026-03-03T09:59:08.426Z

Link: CVE-2026-28772

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-04T08:16:13.333

Modified: 2026-03-04T08:16:13.333

Link: CVE-2026-28772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses