CVE-2026-38056
8.8ST Engineering iDirect · Evolution iQ-Series, 3315-Series, and 9-Series Terminals
A local privilege escalation vulnerability in ST Engineering iDirect terminals allows low-privilege users to gain full administrative control due to improper authorization handling.
Executive summary
A critical local privilege escalation vulnerability in ST Engineering iDirect satellite terminals enables unauthorized administrative access, posing a severe threat to remote and critical infrastructure.
Vulnerability
The vulnerability, classified as CWE-862 (Missing Authorization), exists because the device ships with a pre-configured low-privilege account that can be leveraged to achieve full administrative control. The attacker requires initial access to this low-privilege account, which is factory-provided and does not require additional credentials or brute-forcing.
Business impact
Successful exploitation allows an attacker to gain full administrative control over the satellite modem, which serves as a primary communications link for critical sectors including oil, gas, maritime, and defense. Given the CVSS score of 8.8, this vulnerability represents a high-risk scenario where an attacker could disrupt, monitor, or manipulate sensitive remote communications, leading to significant operational downtime or data compromise.
Remediation
Immediate Action: Update the affected terminals to firmware version 4.5.3.0 or newer via the iDirect Support Portal.
Proactive Monitoring: Monitor management interfaces for unauthorized shell access attempts and review logs for suspicious activity originating from the pre-configured diagnostic user accounts.
Compensating Controls: Restrict access to management interfaces by implementing strict network-level controls, such as VPNs or Access Control Lists (ACLs), to ensure that only trusted entities can reach the administrative endpoints.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The high CVSS score of 8.8 underscores the severity of this flaw, particularly for devices deployed in critical remote infrastructure. Administrators should prioritize the firmware update to version 4.5.3.0 immediately and enforce strict network segmentation to minimize the exposure of management interfaces to unauthorized users.
More ST Engineering iDirect CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Ahmed Alqahtani of Aramco reported this vulnerability to CISA., per the CVE Program record.