VYPR
Vendor

IDirect

Products
2
CVEs
4
Across products
5
Status
Private

Products

2

Recent CVEs

4
  • CVE-2026-38056HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link…

  • CVE-2026-38058HigSep 11, 2026
    risk 0.53cvss 8.1epss 0.00

    The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these…

  • CVE-2026-38057HigJul 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that,…

  • CVE-2026-38059HigJul 10, 2026
    risk 0.49cvss 7.5epss 0.01

    The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC…