Impact
The iDirect iQ200 series exposes the /api/identity and /api/ endpoints without requiring any authentication, representing a CWE‑306 Authentication Bypass. An attacker who can reach the device over the network can retrieve sensitive device data such as the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and firmware version. These identifiers are used for satellite network authentication, allowing a malicious actor to potentially impersonate the terminal or conduct reconnaissance on the broader iDirect infrastructure.
Affected Systems
Affected systems include ST Engineering iDirect 3315‑Series Terminals, 9‑Series Terminals, and Evolution iQ‑Series terminals running firmware versions older than the patched release 4.5.2.2, which is available via the iDirect Support Portal. Devices with the vulnerable firmware can be accessed through the non‑authenticated /api/identity and /api/ endpoints.
Risk and Exploitability
The CVSS score of 8.7 signifies high severity, while the EPSS score of < 1% indicates a very low probability of exploitation at present. The vulnerability is exploitable directly over the network without authentication, making it attractive to attackers who obtain any network access to the device. Although not listed in the CISA KEV catalog, the exposed endpoints enable straightforward enumeration of identifiers that could be used for terminal impersonation or further network reconnaissance.
OpenCVE Enrichment