ZeroHour

CVE-2026-38056

large

Local Privilege Escalation in ST Engineering iDirect iQ200 VSAT Terminal

CVSS 4.0
9.4 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-38056 is a critical local privilege escalation flaw (CWE-862, missing authorization) in the ST Engineering iDirect iQ200 rackmount satellite modem running firmware 23.0.1.0. The iQ200 ships from the factory with a built-in low-privilege technician account intended for maintenance and diagnostics, and an attacker who uses that account — or otherwise gains local shell access — can exploit the missing authorization check, since the attack requires no additional privileges or user interaction. Successful exploitation yields full administrative control of the terminal, with high impact on the device's confidentiality, integrity, and availability and on the satellite communications service it provides, which is often the sole communications link for offshore rigs, vessels, and remote sites. Any organization operating an iQ200 on the affected firmware — particularly in oil and gas, maritime, defense, and remote infrastructure — is affected. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and it was assigned by CISA ICS-CERT in the advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)'.

What to do: Inventory all iQ 200 terminals, record their running firmware version, and upgrade to the fixed release identified in the ST Engineering iDirect / CISA ICS-CERT advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)' (the fixed version is not specified in the available data). Until patching is complete, restrict and rotate the factory-built-in technician account credentials and limit local shell access to trusted personnel, since that pre-configured account is the only access the exploit requires and the terminal is frequently the sole communications link at the site.

Affected
ST Engineering iDirect iQ 200 VSAT terminal (rackmount satellite modem)firmware 23.0.1.0
Estimated exposure
largeon the order of tens of thousands of deployed terminals (estimated; no public install counts) — No public installation counts exist for this model, so the estimate is based on ST Engineering iDirect's role as a leading VSAT terminal supplier and the iQ200's one-terminal-per-rig/vessel/remote-site deployment across oil and gas,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.

Weakness
CWE-862
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

ST Engineering iDirect iQ-Series Terminals (Update A)

CISA advisory details four flaws in ST Engineering iDirect iQ-Series VSAT terminals <=4.5.2.1, enabling device data theft, CSRF-driven reboots, and local privilege escalation.

CISA's Update A to ICSA-26-183-01 covers ST Engineering iDirect iQ-Series, 3315-Series and 9-Series terminals at firmware <=4.5.2.1, deployed across communications, defense, energy and transportation. CVE-2026-38059 exposes unauthenticated /api/identity and /api/ endpoints leaking serial number, DID, TPK, MAC address and firmware version, potentially enabling terminal impersonation; CVE-2026-38057 is a CSRF flaw letting an attacker force terminal reboots and satellite link loss via /api/reboot. CVE-2026-38056 enables local privilege escalation using the factory-configured technician account (CVSS 3.1 8.8, CVSS 4.0 9.4), and CVE-2026-38058 exposes crackable MD5-crypt root password hashes. All four flaws were reported to CISA by Ahmed Alqahtani of Aramco.