ZeroHour
CISA Advisoriespublished ()ingested CISA

ST Engineering iDirect iQ-Series Terminals (Update A)

AI summary · glm-5.3-flash

CISA advisory details four flaws in ST Engineering iDirect iQ-Series VSAT terminals <=4.5.2.1, enabling device data theft, CSRF-driven reboots, and local privilege escalation.

CISA's Update A to ICSA-26-183-01 covers ST Engineering iDirect iQ-Series, 3315-Series and 9-Series terminals at firmware <=4.5.2.1, deployed across communications, defense, energy and transportation. CVE-2026-38059 exposes unauthenticated /api/identity and /api/ endpoints leaking serial number, DID, TPK, MAC address and firmware version, potentially enabling terminal impersonation; CVE-2026-38057 is a CSRF flaw letting an attacker force terminal reboots and satellite link loss via /api/reboot. CVE-2026-38056 enables local privilege escalation using the factory-configured technician account (CVSS 3.1 8.8, CVSS 4.0 9.4), and CVE-2026-38058 exposes crackable MD5-crypt root password hashes. All four flaws were reported to CISA by Ahmed Alqahtani of Aramco.

  • Four CVEs affect iQ-Series, 3315-Series and 9-Series terminals at firmware <=4.5.2.1.
  • Unauthenticated API endpoints leak DID and TPK identifiers used for satellite network authentication.
  • CSRF on /api/reboot can force reboots and sustained denial of satellite connectivity.
  • Local privilege escalation scores 8.8 (CVSS 3.1) and 9.4 (CVSS 4.0); password hashes crackable offline.
  • VSAT terminals serve as sole communications links for offshore rigs, vessels and remote defense sites.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-38056
Local Privilege Escalation in ST Engineering iDirect iQ200 VSAT Terminal

CVE-2026-38056 is a critical local privilege escalation flaw (CWE-862, missing authorization) in the ST Engineering iDirect iQ200 rackmount satellite modem running firmware 23.0.1.0. The iQ200 ships from the factory with a built-in low-privilege technician account intended for maintenance and diagnostics, and an attacker who uses that account — or otherwise gains local shell access — can exploit the missing authorization check, since the attack requires no additional privileges or user interaction. Successful exploitation yields full administrative control of the terminal, with high impact on the device's confidentiality, integrity, and availability and on the satellite communications service it provides, which is often the sole communications link for offshore rigs, vessels, and remote sites. Any organization operating an iQ200 on the affected firmware — particularly in oil and gas, maritime, defense, and remote infrastructure — is affected. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, no public proof-of-concept is known, and it was assigned by CISA ICS-CERT in the advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)'.

Do: Inventory all iQ 200 terminals, record their running firmware version, and upgrade to the fixed release identified in the ST Engineering iDirect / CISA ICS-CERT advisory 'ST Engineering iDirect iQ-Series Terminals (Update A)' (the fixed version is not specified in the available data). Until patching is complete, restrict and rotate the factory-built-in technician account credentials and limit local shell access to trusted personnel, since that pre-configured account is the only access the exploit requires and the terminal is frequently the sole communications link at the site.

9.4
  • ST Engineering iDirect iQ 200 VSAT terminal (rackmount satellite modem) firmware 23.0.1.0
largeon the order of tens of thousands of deployed terminals (estimated; no public install counts)
CVE-2026-38057
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication.

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.

NVD description · AI analysis pending
7.0<1%
CVE-2026-38058
Sensitive Password Hash Exposure in ST Engineering iDirect iQ200 VSAT Terminal

The iQ200 VSAT terminal exposes a web endpoint that returns the complete device configuration as JSON, including a SECURITY section that contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user who holds valid web credentials, including low-privileged accounts, can call this endpoint and retrieve those hashes. Because MD5-crypt is a fast legacy hash, the attacker can crack the hashes offline on commodity hardware and recover the root SSH and web admin passwords, potentially gaining privileged control of the terminal and the network it anchors. Affected organizations are satellite service providers, enterprises, and other operators deploying iQ200 (and, per the related advisory, iQ-Series) VSAT terminals. There is no CISA KEV listing, no public proof-of-concept, and no known exploitation at this time; the issue was assigned by CISA ICS-CERT with a CVSS 4.0 score of 8.6 (High).

Do: Consult the ST Engineering iDirect advisory (iQ-Series Terminals, Update A) and apply the fixed firmware it specifies once identified, since no fixed version is given in the available data. Until patched, restrict access to the terminal's web management interface to trusted management networks or VPN access, and minimize or eliminate low-privileged web accounts whose credentials could be used to pull the configuration. Because MD5-crypt hashes can be cracked quickly offline, treat any account that could have queried the endpoint as potentially exposed and rotate the root SSH and web admin passwords.

8.6
  • ST Engineering iDirect iQ200 VSAT terminal
  • ST Engineering iDirect iQ-Series VSAT terminals (per related advisory)
moderateon the order of tens of thousands of deployed terminals (iDirect's large VSAT installed base, with iQ200 a newer-generation remote); only units with remotely…
CVE-2026-38059
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication.

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.

NVD description · AI analysis pending
8.7<1%
Full article996 words · extracted from cisa.gov · click to collapse

View CSAF

Summary

Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.

The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:

  • Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
  • 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
  • 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CVSS Vendor Equipment Vulnerabilities
v3 8.8 ST Engineering iDirect ST Engineering iDirect iQ-Series Terminals  Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere

Background

  • Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems
  • Countries/Areas Deployed: Worldwide
  • Company Headquarters Location: United States

Vulnerabilities

Expand All +

CVE-2026-38059

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.

View CVE Details


Affected Products

ST Engineering iDirect iQ-Series Terminals (Update A)

Vendor:
ST Engineering iDirect

Product Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1

Product Status:
known_affected

Relevant CWE: CWE-306 Missing Authentication for Critical Function


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

CVE-2026-38057

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.

View CVE Details


Affected Products

ST Engineering iDirect iQ-Series Terminals (Update A)

Vendor:
ST Engineering iDirect

Product Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1

Product Status:
known_affected

Relevant CWE: CWE-352 Cross-Site Request Forgery (CSRF)


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
4.0 7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

CVE-2026-38056

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.

View CVE Details


Affected Products

ST Engineering iDirect iQ-Series Terminals (Update A)

Vendor:
ST Engineering iDirect

Product Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1

Product Status:
known_affected

Relevant CWE: CWE-862 Missing Authorization


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
4.0 9.4 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CVE-2026-38058

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

View CVE Details


Affected Products

ST Engineering iDirect iQ-Series Terminals (Update A)

Vendor:
ST Engineering iDirect

Product Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1

Product Status:
known_affected

Relevant CWE: CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere


Metrics

CVSS Version Base Score Base Severity Vector String
3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Acknowledgments

  • Ahmed Alqahtani of Aramco reported these vulnerabilities to CISA.

Legal Notice and Terms of Use

This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).


Recommended Practices

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.

Locate control system networks and remote devices behind firewalls and isolating them from business networks.

CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.

CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.

Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies.

Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

CISA also recommends users take the following measures to protect themselves from social engineering attacks:

Do not click web links or open attachments in unsolicited email messages.

Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.

Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.


Revision History

  • Initial Release Date: 2026-07-02
Date Revision Summary
2026-07-02 1 Initial Publication
2026-09-10 2 Update A - Updated Vulnerabilities and CVSS 4.0 score in Executive Summary. Added CVE-2026-38056 and CVE-2026-38058. Updated Mitigation section with newest product version.

Legal Notice and Terms of Use

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01