Description
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
Published: 2026-09-11
Score: 9.4 Critical
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a local user account, pre‑configured on the device, to gain administrative privileges without additional authentication. An attacker who can log into the system with the low‑privilege maintenance account can exploit the missing authorization check to perform arbitrary commands, effectively elevating to full device control. This breach could lead to unauthorized configuration changes, denial of service, or exploitation of the device as part of a wider network compromise. The weakness is a classic missing authorization flaw (CWE-862).

Affected Systems

Affected products include ST Engineering iDirect iQ‑Series terminals such as the 3315‑Series, 9‑Series, and Evolution iQ‑Series devices. The flaw was observed in the iQ200 VSAT modem running firmware 23.0.1.0. The vendor recommends updating to firmware version 4.5.3.0 or newer to remediate the issue.

Risk and Exploitability

With a CVSS score of 9.4 the vulnerability is considered critical. Since it is a local privilege escalation, an attacker must already have physical or local console access to the satellite modem, but the pre‑configured low‑privilege account is readily available to field technicians. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, however the device often serves as the sole communication link for offshore oil and gas rigs, maritime vessels, and remote industrial sites. If compromised, the device could be used to tamper with telemetry, disrupt critical communications, or pivot to other network assets, making exploitation a high‑risk event.

Generated by OpenCVE AI on September 11, 2026 at 16:23 UTC.

Remediation

Vendor Solution

ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer. Registered users are able to download patches from the iDirect Support Portal:  https://support.idirect.net https://support.idirect.net/ * Restrict management interfaces to trusted networks (e.g., VPN, ACLs). * Avoid exposing administrative APIs to the public internet. * Enforce strong authentication practices. * Monitor for anomalous API activity and unexpected device reboots.


OpenCVE Recommended Actions

  • Update the firmware to version 4.5.3.0 or newer.
  • Restrict management interfaces to trusted networks such as VPNs or ACLs.
  • Avoid exposing administrative APIs to the public internet.
  • Enforce strong authentication practices for all management access.
  • Monitor for anomalous API activity and unexpected device reboots.

Generated by OpenCVE AI on September 11, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
Title ST Engineering iDirect iQ-Series Terminals Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T15:02:42.163Z

Reserved: 2026-04-06T08:25:37.731Z

Link: CVE-2026-38056

cve-icon Vulnrichment

Updated: 2026-09-11T15:02:36.985Z

cve-icon NVD

Status : Received

Published: 2026-09-11T15:17:01.070

Modified: 2026-09-11T16:17:05.940

Link: CVE-2026-38056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses