The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

Project Subscriptions

Vendors Products
St Engineering Idirect Subscribe
3315-series Terminals Subscribe
9-series Terminals Subscribe
Evolution Iq‑series Terminals Subscribe
Advisories

No advisories yet.

Fixes

Solution

ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer. Registered users are able to download patches from the iDirect Support Portal:  https://support.idirect.net https://support.idirect.net/ * Restrict management interfaces to trusted networks (e.g., VPN, ACLs). * Avoid exposing administrative APIs to the public internet. * Enforce strong authentication practices. * Monitor for anomalous API activity and unexpected device reboots.


Workaround

No workaround given by the vendor.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared St Engineering Idirect
St Engineering Idirect 3315-series Terminals
St Engineering Idirect 9-series Terminals
St Engineering Idirect evolution Iq‑series Terminals
Vendors & Products St Engineering Idirect
St Engineering Idirect 3315-series Terminals
St Engineering Idirect 9-series Terminals
St Engineering Idirect evolution Iq‑series Terminals

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
Title ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T15:02:06.162Z

Reserved: 2026-04-06T08:25:37.731Z

Link: CVE-2026-38058

cve-icon Vulnrichment

Updated: 2026-09-11T15:02:02.928Z

cve-icon NVD

Status : Received

Published: 2026-09-11T15:17:01.407

Modified: 2026-09-11T16:17:06.080

Link: CVE-2026-38058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:56:10Z

Weaknesses