CVE-2026-38058
8.1ST Engineering iDirect · Evolution iQ‑Series, 3315-Series, and 9-Series terminals
A configuration exposure vulnerability in iDirect VSAT terminals allows authenticated users to retrieve sensitive MD5 password hashes via a JSON API endpoint.
Executive summary
An authenticated information exposure vulnerability in ST Engineering iDirect VSAT terminals permits the retrieval of administrative password hashes, posing a critical risk of full device compromise.
Vulnerability
The device configuration endpoint insecurely exposes sensitive data, including MD5-crypt password hashes for root SSH and web administration accounts, to any user with valid web credentials. This flaw (CWE-497) allows an attacker to perform offline brute-force attacks to recover cleartext credentials.
Business impact
The exposure of administrative credentials directly facilitates unauthorized access to critical communication infrastructure. With a CVSS score of 8.1, the vulnerability represents a high risk, as it grants attackers the ability to escalate privileges and establish persistence on VSAT hardware. Successful exploitation could lead to total loss of device control, potential interception of satellite communications, and significant operational disruption.
Remediation
Immediate Action: Update affected terminals to software version 4.5.3.0 or newer via the iDirect Support Portal.
Proactive Monitoring: Monitor management interface access logs for unusual patterns or repeated requests to configuration endpoints.
Compensating Controls: Restrict access to device management interfaces by placing them behind VPNs or utilizing Access Control Lists (ACLs) to ensure they are not exposed to the public internet.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
This vulnerability presents a significant risk to the integrity of network hardware. Organizations must prioritize the deployment of firmware version 4.5.3.0 across all affected VSAT terminals. Until patching can be completed, ensure that management interfaces are strictly segmented from untrusted networks to prevent unauthorized access to the vulnerable API endpoint.
More ST Engineering iDirect CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Ahmed Alqahtani of Aramco reported this vulnerability to CISA., per the CVE Program record.