VYPR

iQ200

by ST Engineering IDirect

CVEs (1)

  • CVE-2026-38058higJul 2, 2026
    risk 0.53cvss 8.1epss

    The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these…