AI analysis
CVE-2026-38056 is a critical local privilege escalation flaw (CWE-862, missing authorization) in the ST Engineering iDirect iQ200 rackmount satellite modem running firmware 23.0.1.0. The iQ200 ships from the factory with a built-in low-privilege technician account intended for maintenance and diagnostics, and an attacker who uses that account — or otherwise gains local shell access — can exploit the missing authorization check, since the attack requires no additional privileges or user interaction. Successful exploitation yields full administrative control of the terminal, with high impact on the device's confidentiality, integrity, and availability and on the satellite communications service it provides, which is often the sole communications link for offshore rigs, vessels, and remote sites. Any organization operating an iQ200 on the affected firmware — particularly in oil and gas, maritime, defense, and remote infrastructure — is affected. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and it was assigned by CISA ICS-CERT in the advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)'.
What to do: Inventory all iQ 200 terminals, record their running firmware version, and upgrade to the fixed release identified in the ST Engineering iDirect / CISA ICS-CERT advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)' (the fixed version is not specified in the available data). Until patching is complete, restrict and rotate the factory-built-in technician account credentials and limit local shell access to trusted personnel, since that pre-configured account is the only access the exploit requires and the terminal is frequently the sole communications link at the site.
Affected
| ST Engineering iDirect iQ 200 VSAT terminal (rackmount satellite modem) | firmware 23.0.1.0 |
Estimated exposure
largeon the order of tens of thousands of deployed terminals (estimated; no public install counts) — No public installation counts exist for this model, so the estimate is based on ST Engineering iDirect's role as a leading VSAT terminal supplier and the iQ200's one-terminal-per-rig/vessel/remote-site deployment across oil and gas,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.