Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:
- Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
- 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
- 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CVSS
Vendor
Equipment
Vulnerabilities
v3 8.8
ST Engineering iDirect
ST Engineering iDirect iQ-Series Terminals
Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere
Background
- Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
Expand All +
CVE-2026-38059
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.
View CVE Details
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:ST Engineering iDirect
Product Version:ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1
Product Status:known_affected
Remediations
MitigationST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.
MitigationRegistered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Metrics
CVSS Version
Base Score
Base Severity
Vector String
3.1
7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0
8.7
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-38057
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
View CVE Details
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:ST Engineering iDirect
Product Version:ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1
Product Status:known_affected
Remediations
MitigationST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.
MitigationRegistered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Metrics
CVSS Version
Base Score
Base Severity
Vector String
3.1
8.1
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
4.0
7
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-38056
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
View CVE Details
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:ST Engineering iDirect
Product Version:ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1
Product Status:known_affected
Remediations
MitigationST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.
MitigationRegistered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Metrics
CVSS Version
Base Score
Base Severity
Vector String
3.1
8.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
4.0
9.4
CRITICAL
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVE-2026-38058
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
View CVE Details
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:ST Engineering iDirect
Product Version:ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1
Product Status:known_affected
Remediations
MitigationST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.
MitigationRegistered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Metrics
CVSS Version
Base Score
Base Severity
Vector String
3.1
8.1
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
4.0
8.6
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- Ahmed Alqahtani of Aramco reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Locate control system networks and remote devices behind firewalls and isolating them from business networks.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
Do not click web links or open attachments in unsolicited email messages.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-07-02
Date
Revision
Summary
2026-07-02
1
Initial Publication
2026-09-10
2
Update A - Updated Vulnerabilities and CVSS 4.0 score in Executive Summary. Added CVE-2026-38056 and CVE-2026-38058. Updated Mitigation section with newest product version.