Description
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
Published: 2026-09-11
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the iDirect iQ200 VSAT terminal’s configuration retrieval endpoint, which returns a complete JSON representation of the device’s configuration. The JSON includes a SECURITY block that contains MD5‑crypt hashed passwords for the root SSH and web administration accounts. Because the endpoint is accessible to any user with valid web credentials, an attacker can obtain these hashes and later perform offline dictionary or brute‑force attacks to recover the plaintext passwords. This breach of confidentiality can lead to unauthorized access to administrative functions and potentially full device takeover if the root accounts are compromised.

Affected Systems

The affected devices are ST Engineering iDirect 3315‑Series terminals, 9‑Series terminals, and Evolution iQ‑Series terminals. The vendor advisories recommend updating each device to firmware version 4.5.3.0 or newer to resolve the issue. No specific pre‑update version that was affected is provided in the advisory; any device running a firmware version older than the recommended fix should be considered vulnerable until it is patched.

Risk and Exploitability

The vulnerability has a CVSS score of 8.6, indicating a high severity of information disclosure. EPSS is not provided, and the vulnerability is not listed in CISA’s KEV catalog. The exploitation requires a user to possess valid web credentials and an active network connection to the management interface, making the attack vector likely to be via the web UI or APIs that are publicly reachable. Once a valid credential is available, the attacker can retrieve the configuration JSON and offline crack the MD5‑crypt hashes, potentially allowing them to gain full administrative control of the terminal.

Generated by OpenCVE AI on September 11, 2026 at 16:23 UTC.

Remediation

Vendor Solution

ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer. Registered users are able to download patches from the iDirect Support Portal:  https://support.idirect.net https://support.idirect.net/ * Restrict management interfaces to trusted networks (e.g., VPN, ACLs). * Avoid exposing administrative APIs to the public internet. * Enforce strong authentication practices. * Monitor for anomalous API activity and unexpected device reboots.


OpenCVE Recommended Actions

  • Apply the latest firmware release (4.5.3.0 or newer) to all affected terminals.
  • Restrict the device’s management interface to trusted networks (e.g., VPN or ACLs) and block public‑internet exposure.
  • Enforce strong authentication, including updating or disabling weak root passwords for SSH and web administration.
  • Monitor API activity for anomalies and unexpected reboots to detect attempted exploitation.

Generated by OpenCVE AI on September 11, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
Title ST Engineering iDirect iQ-Series Terminals Exposure of Sensitive System Information to an Unauthorized Control Sphere
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-11T15:02:06.162Z

Reserved: 2026-04-06T08:25:37.731Z

Link: CVE-2026-38058

cve-icon Vulnrichment

Updated: 2026-09-11T15:02:02.928Z

cve-icon NVD

Status : Received

Published: 2026-09-11T15:17:01.407

Modified: 2026-09-11T16:17:06.080

Link: CVE-2026-38058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:30:08Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere