Junglewise Threat Intelligence

CVE-2026-38056: iDirect iQ200 local privilege escalation

CVE-2026-38056 · Severity: high · CVSS 8.8 · Published 2026-09-11

Executive brief

The iDirect iQ200 is a satellite modem deployed as the primary communications link for offshore rigs, vessels, and remote sites in oil and gas and maritime operations. A vulnerability in firmware 23.0.1.0 allows a technician with the pre-configured low-privilege local account to escalate to full administrative control, potentially compromising critical infrastructure communications and operational continuity.

Technical details

A local privilege escalation vulnerability exists in iDirect iQ200 firmware 23.0.1.0 that allows an authenticated low-privilege user to gain administrative (root) access. The device ships with a pre-configured local user account intended for field technicians performing maintenance and diagnostics. An attacker with access to this account can exploit the flaw to elevate privileges without requiring additional credentials. Once administrative access is obtained, an attacker can fully compromise the device, including reading sensitive configuration, intercepting satellite communications, or disabling operations. Patches or firmware updates addressing this issue should be obtained from iDirect support.

Affected products

  • iDirect iQ200 23.0.1.0

Timeline

  • 2026-09-11: disclosed

References

Related threats