Executive brief
ST Engineering iDirect iQ-Series satellite terminals contain a security flaw where sensitive device information is accessible without a password. These terminals are used for satellite communications in critical sectors like defense, energy, and transportation. An attacker could use this information to impersonate a legitimate terminal on the satellite network or conduct further targeted attacks against the organization's infrastructure.
Technical details
The iDirect iQ200 and related iQ-Series terminals suffer from missing authentication (CWE-306) on the /api/identity and /api/ REST API endpoints. An unauthenticated attacker with network access to the device can retrieve sensitive metadata, including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and firmware version. The DID and TPK are critical components used for satellite network authentication within the iDirect platform; their exposure could facilitate terminal impersonation and network reconnaissance. The vulnerability is addressed in software version 4.5.2.2.
Affected products
- ST Engineering iDirect Evolution iQ-Series terminals <= 4.5.2.1
- ST Engineering iDirect 3315-Series terminals <= 4.5.2.1
- ST Engineering iDirect 9-Series terminals <= 4.5.2.1
Timeline
- 2026-07-02: advisory: Initial CISA ICSA-26-183-01 publication
- 2026-07-10: disclosed: NVD publication of CVE-2026-38059
- 2026-07-10: patched: Version 4.5.2.2 released to address the issue