Impact
The vulnerability allows a local user account, pre‑configured on the device, to gain administrative privileges without additional authentication. An attacker who can log into the system with the low‑privilege maintenance account can exploit the missing authorization check to perform arbitrary commands, effectively elevating to full device control. This breach could lead to unauthorized configuration changes, denial of service, or exploitation of the device as part of a wider network compromise. The weakness is a classic missing authorization flaw (CWE-862).
Affected Systems
Affected products include ST Engineering iDirect iQ‑Series terminals such as the 3315‑Series, 9‑Series, and Evolution iQ‑Series devices. The flaw was observed in the iQ200 VSAT modem running firmware 23.0.1.0. The vendor recommends updating to firmware version 4.5.3.0 or newer to remediate the issue.
Risk and Exploitability
With a CVSS score of 9.4 the vulnerability is considered critical. Since it is a local privilege escalation, an attacker must already have physical or local console access to the satellite modem, but the pre‑configured low‑privilege account is readily available to field technicians. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, however the device often serves as the sole communication link for offshore oil and gas rigs, maritime vessels, and remote industrial sites. If compromised, the device could be used to tamper with telemetry, disrupt critical communications, or pivot to other network assets, making exploitation a high‑risk event.
OpenCVE Enrichment