PatchSiren

ST Engineering iDirect CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ST Engineering iDirect CVE published 2026-09-11

CVE-2026-38058

CVE-2026-38058 debrief based on the supplied source corpus. The iDirect iQ200 VSAT terminal has a vulnerability that allows extraction of MD5-crypt password hashes, potentially leading to unauthorized access. Defenders should prioritize verification of exposure, assess password hash strength, and consider updates or patches. The vulnerability affects the device's configuration endpoint, which returns comp [truncated]

CRITICAL ST Engineering iDirect CVE published 2026-09-11

CVE-2026-38056

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. The device ships from the factory with a pre-configured low-privilege local user acc [truncated]

HIGH ST Engineering iDirect CVE published 2026-07-10

CVE-2026-38059

The CVE-2026-38059 vulnerability exposes unauthenticated API endpoints on iDirect iQ200 devices, allowing attackers to retrieve sensitive information. This issue, rated High severity with a CVSS score of 8.7, was published on 2026-07-10T15:16:39.563Z and last modified on 2026-09-11T15:17:01.553Z. The vulnerability allows unauthenticated access to sensitive device information, including serial number, Devi [truncated]