PatchSiren cyber security CVE debrief
CVE-2026-38058 ST Engineering iDirect CVE debrief
CVE-2026-38058 debrief based on the supplied source corpus. The iDirect iQ200 VSAT terminal has a vulnerability that allows extraction of MD5-crypt password hashes, potentially leading to unauthorized access. Defenders should prioritize verification of exposure, assess password hash strength, and consider updates or patches. The vulnerability affects the device's configuration endpoint, which returns complete device configuration as JSON, including SECURITY section with MD5-crypt password hashes for root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. The CVE record and NVD entry also
- Vendor
- ST Engineering iDirect
- Product
- Evolution iQ‑Series terminals
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-11
- Original CVE updated
- 2026-09-11
- Advisory published
- 2026-09-11
- Advisory updated
- 2026-09-11
Who should care
Defenders responsible for iDirect iQ200 VSAT terminals, network administrators, and security teams should assess exposure and prioritize verification of device configurations and password hash strength.
Why it matters
CVE-2026-38058 is a high-severity vulnerability in iDirect iQ200 VSAT terminals that allows extraction of MD5-crypt password hashes, potentially leading to unauthorized access. Defenders should prioritize verification of exposure, assess password hash strength, and consider updates or patches.
- Potential for offline cracking of MD5-crypt password hashes
- Exposure of sensitive device configuration data
- Risk of unauthorized access to iDirect iQ200 VSAT terminals
- Need for verification of device configurations and password hash strength
Technical summary
The iDirect iQ200 VSAT terminal has an endpoint that returns the complete device configuration as JSON, including MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and potentially crack them offline using commodity hardware. The vulnerability has a high severity score of 8.6 and affects the device's configuration endpoint. The CVE record and NVD entry provide details on the vulnerability, including the affected device and the potential for extracting MD5-crypt password hashes.
Defensive priority
Defenders should prioritize verifying exposure of iDirect iQ200 VSAT terminals and assessing the strength of MD5-crypt password hashes.
Recommended defensive actions
- Verify exposure of iDirect iQ200 VSAT terminals in the environment
- Assess the strength of MD5-crypt password hashes for root SSH and web administration accounts
- Consider updating or patching affected devices
- Monitor for potential offline cracking attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including the affected device and the potential for extracting MD5-crypt password hashes. The iDirect iQ200 VSAT terminal's configuration endpoint returns complete device configuration as JSON, including SECURITY section with MD5-crypt password hashes for root SSH and web administration accounts. The hashes can be extracted by any user with valid web credentials and potentially cracked offline using commodity hardware. The vulnerability has a high severity score of 8.6
Sources and references
Verified primary and authoritative sources
-
CVE-2026-38058 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-38058
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-38058 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38058
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json
-
Source reference
Unverified legacy reference
URL: https://support.idirect.net/
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.