Back to news

Four Bugs in iDirect VSAT Terminals Leak Satellite Network Keys

Share:
Four Bugs in iDirect VSAT Terminals Leak Satellite Network Keys

The Cybersecurity and Infrastructure Security Agency published advisory ICSA-26-183-01 on July 2, 2026, covering four vulnerabilities in ST Engineering iDirect's Evolution iQ-Series, 3315-Series, and 9-Series satellite terminals, then updated it on September 10, 2026. The affected VSAT modems carry data links for ships, offshore energy platforms, defense sites, and emergency-response teams running firmware 4.5.2.1 or earlier.

Four ways into the terminal

CVE-2026-38059, rated 7.5 on the CVSS scale, lets anyone on the network query the terminal's /api/identity and /api/ REST endpoints without logging in. The response hands back the serial number, MAC address, exact firmware version, and two identifiers used for satellite network authentication: the Device ID and the Terminal Private Key, information an attacker could use to impersonate the terminal on the operator's network.

CVE-2026-38058, at CVSS 8.1, is worse for anyone who already holds a low-level web account. The device's configuration endpoint returns its full settings in JSON, including a security section with MD5-crypt password hashes for the root SSH and web administration accounts. Those hashes can be cracked offline on ordinary hardware, according to a write-up of the flaw tracked by threat-intelligence vendor OffSeq.

CVE-2026-38057, also CVSS 8.1, is a cross-site request forgery bug. The /api/reboot endpoint accepts a POST request authenticated only by a session cookie that lacks the SameSite attribute. A logged-in administrator who visits a malicious web page can unknowingly trigger a reboot and drop the satellite link, and repeating the trick sustains a denial-of-service condition.

CVE-2026-38056 is the most severe, at CVSS 8.8: a local privilege escalation flaw in the terminal's firmware that lets a low-privileged process gain root control of the device.

An oil company researcher, and a wider pattern

Ahmed Alqahtani of Saudi Aramco reported all four bugs to CISA, a detail that points to where these terminals live: offshore rigs and tankers with no local IT staff, running for years on firmware nobody gets around to patching. That pattern is not unique to iDirect. A Security Boulevard write-up published in August 2026 describes a single SNMP scan turning up 437 Hughes multimedia VSAT terminals across 13 networks, 28 organizations, and 15 countries, many still running operating systems that stopped receiving updates five to eight years ago.

The stakes for that gap are rising. Maritime cybersecurity firm Cydome tracked satellite-connected edge devices, including VSAT terminals, in 22 percent of maritime cyberattacks recorded in 2025, up from 3 percent in 2024, according to its analysis reported by New Space Economy.

Fix

ST Engineering iDirect has released corrected firmware for all three affected terminal families. CISA's advisory recommends restricting the terminal's management interface to trusted networks, monitoring for unexpected reboots or configuration changes, and applying the update after testing. No public exploitation has been reported to date, but the Device ID and Terminal Private Key exposed by CVE-2026-38059 are the same identifiers the iDirect platform uses to authenticate a terminal onto the satellite network, so a leaked pair has value well beyond the single device it came from.

First detailed in CISA advisory ICSA-26-183-01, updated September 10, 2026.