Junglewise Threat Intelligence

CVE-2026-38058: iDirect iQ200 configuration endpoint information disclosure

CVE-2026-38058 · Severity: high · CVSS 8.1 · Published 2026-09-11

Executive brief

The iDirect iQ200 VSAT terminal is a satellite communication device used to establish broadband connectivity in remote locations. An unauthenticated or low-privileged attacker with valid web credentials can access an endpoint that exposes the complete device configuration, including MD5 password hashes for root SSH and web administration accounts. These hashes can be cracked offline using commodity hardware, potentially allowing an attacker to gain full administrative control of the terminal and compromise satellite network communications.

Technical details

This is an information disclosure vulnerability affecting a configuration management endpoint on the iDirect iQ200 VSAT terminal. The vulnerable endpoint returns the complete device configuration as JSON and inadvertently exposes the SECURITY section containing MD5-crypt password hashes for root SSH and web administration accounts. An authenticated user with valid web credentials can extract these hashes and crack them offline using commodity password cracking tools. The vulnerability allows privilege escalation from standard user access to administrative control. Patch availability has not been confirmed in the advisory text.

Affected products

  • iDirect iQ200 <UNKNOWN>

Timeline

  • 2026-09-11: disclosed

References

Related threats