VYPR

iQ-Series Terminals

by ST Engineering IDirect

CVEs (2)

  • CVE-2026-38056higJul 2, 2026
    risk 0.57cvss 8.8epss

    A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link…

  • CVE-2026-38058higJul 2, 2026
    risk 0.53cvss 8.1epss

    The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these…