VYPR
High severity8.1NVD Advisory· Published Jul 2, 2026· Updated Sep 10, 2026

ST Engineering iDirect iQ-Series Terminals (Update A)

CVE-2026-38058

Description

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

Affected products

2

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.