PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-38058 ST Engineering iDirect CVE debrief

CVE-2026-38058 debrief based on the supplied source corpus. The iDirect iQ200 VSAT terminal has a vulnerability that allows extraction of MD5-crypt password hashes, potentially leading to unauthorized access. Defenders should prioritize verification of exposure, assess password hash strength, and consider updates or patches. The vulnerability affects the device's configuration endpoint, which returns complete device configuration as JSON, including SECURITY section with MD5-crypt password hashes for root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware. The CVE record and NVD entry also

Vendor
ST Engineering iDirect
Product
Evolution iQ‑Series terminals
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Defenders responsible for iDirect iQ200 VSAT terminals, network administrators, and security teams should assess exposure and prioritize verification of device configurations and password hash strength.

Why it matters

CVE-2026-38058 is a high-severity vulnerability in iDirect iQ200 VSAT terminals that allows extraction of MD5-crypt password hashes, potentially leading to unauthorized access. Defenders should prioritize verification of exposure, assess password hash strength, and consider updates or patches.

  • Potential for offline cracking of MD5-crypt password hashes
  • Exposure of sensitive device configuration data
  • Risk of unauthorized access to iDirect iQ200 VSAT terminals
  • Need for verification of device configurations and password hash strength

Technical summary

The iDirect iQ200 VSAT terminal has an endpoint that returns the complete device configuration as JSON, including MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and potentially crack them offline using commodity hardware. The vulnerability has a high severity score of 8.6 and affects the device's configuration endpoint. The CVE record and NVD entry provide details on the vulnerability, including the affected device and the potential for extracting MD5-crypt password hashes.

Defensive priority

Defenders should prioritize verifying exposure of iDirect iQ200 VSAT terminals and assessing the strength of MD5-crypt password hashes.

Recommended defensive actions

  • Verify exposure of iDirect iQ200 VSAT terminals in the environment
  • Assess the strength of MD5-crypt password hashes for root SSH and web administration accounts
  • Consider updating or patching affected devices
  • Monitor for potential offline cracking attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including the affected device and the potential for extracting MD5-crypt password hashes. The iDirect iQ200 VSAT terminal's configuration endpoint returns complete device configuration as JSON, including SECURITY section with MD5-crypt password hashes for root SSH and web administration accounts. The hashes can be extracted by any user with valid web credentials and potentially cracked offline using commodity hardware. The vulnerability has a high severity score of 8.6

Sources and references

Verified primary and authoritative sources

  • CVE-2026-38058 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-38058

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-38058 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-38058

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.