Vulnerability in iDirect iQ200 VSAT Terminal Exposes Sensitive Configuration Data
CVE-2026-38058

8.6HIGH

What is CVE-2026-38058?

The iDirect iQ200 VSAT terminal has a significant security vulnerability that allows authenticated users to access the complete configuration of the device in JSON format, including sensitive information such as the SECURITY section. This section contains MD5-crypt password hashes for both the root SSH and web administration accounts. Once these hashes are obtained, an attacker can crack them offline using readily available hardware, posing a severe risk to the integrity of the system. This exposure can lead to unauthorized access and control over the VSAT terminal, highlighting the need for immediate security measures.

Affected Version(s)

3315-Series terminals 0 <= 4.5.2.1

9-Series Terminals 0 <= 4.5.2.1

Evolution iQ‑Series terminals 0 <= 4.5.2.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Alqahtani of Aramco reported this vulnerability to CISA.
.