Local Privilege Escalation Vulnerability in iDirect iQ200 VSAT Terminal
CVE-2026-38056

9.4CRITICAL

What is CVE-2026-38056?

A local privilege escalation vulnerability has been discovered in the iDirect iQ200 VSAT terminal, specifically affecting the firmware version 23.0.1.0. The iQ200 serves as a critical communications link, particularly in sectors such as oil and gas, maritime, and remote operations. The device is shipped with a default low-privilege local user account, designed for field technicians needing shell access for maintenance and diagnostics. However, this built-in account can be exploited to gain unauthorized administrative control over the device, posing serious risks to the integrity of communications in sensitive operations. No additional credentials are required for exploitation, making the vulnerability particularly concerning for operators relying on this essential technology.

Affected Version(s)

3315-Series terminals 0 <= 4.5.2.1

9-Series Terminals 0 <= 4.5.2.1

Evolution iQ‑Series terminals 0 <= 4.5.2.1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Alqahtani of Aramco reported this vulnerability to CISA.
.