Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-38056: iDirect iQ200 VSAT terminal can grant admin rights
CVE-2026-38056 · published 14 days ago
Summary
The iDirect iQ200 satellite modem (firmware 23.0.1.0) lets a low‑privilege technician account take full control of the device. Because the built‑in account is present on every unit, an attacker with local access can obtain administrative privileges without needing to guess passwords. Apply the vendor’s firmware update or disable the default account until the patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| st engineering idirect | evolution iq‑series terminals | <= 4.5.2.1 |
| st engineering idirect | 3315-series terminals | <= 4.5.2.1 |
| st engineering idirect | 9-series terminals | <= 4.5.2.1 |
Original advisory text
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defen...
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
Severity
9.4
Critical
CVSS 3.1: 8.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published11 Sep 2026
Updated25 Sep 2026
First seen11 Sep 2026
Track software like this
Free during beta