A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0.
A built-in technician account can gain administrative control of affected iDirect satellite terminals. The flaw requires local access, but no extra credentials or user action.
- Severity
- HighCVSS 3.1 · 8.8 · hq.dhs.gov
- Fix
- Fixed in 4.5.3.0
- Affected versions
- through 4.5.2.1; through 4.5.2.1; through 4.5.2.1
- Weakness
- CWE-862Missing Authorization
- Affects
- Evolution iQ‑Series terminals+2 more
- Exploited
- Not confirmedNo confirmation recorded
- CISA SSVC
- No known exploitationAutomatable: no · Technical impact: total
- EU ID
- EUVD-2026-76127ENISA vulnerability database
How it works
- The terminal ships with a built-in account for local maintenance and diagnostics.
- That account supplies the local shell access needed for this flaw.
- The software fails to enforce the account's intended limits, allowing higher privileges.
- The retrieved evidence does not identify the exact command or action that triggers this failure.
What to do
If you manage Evolution iQ-Series, 3315-Series, or 9-Series terminals, check whether each runs software 4.5.2.1 or earlier. Treat an iQ200 running firmware 23.0.1.0 as specifically covered by this advisory.
Update affected terminals to software version 4.5.3.0 or newer. Download the update through the iDirect Support Portal. Until updated, restrict management access to trusted networks and keep administrative interfaces off the public internet.
Technical details
Affected software: Evolution iQ‑Series terminalsby ST Engineering iDirect, 3315-Series terminalsby ST Engineering iDirect, 9-Series Terminalsby ST Engineering iDirect
CVE-2026-38056 is a local privilege escalation flaw caused by missing authorization controls. The built-in low-privilege technician account provides the initial shell access, without requiring additional stolen or guessed credentials. CISA lists Evolution iQ-Series, 3315-Series, and 9-Series terminals through 4.5.2.1 as affected. Version 4.5.3.0 is listed as unaffected.
Severity breakdown
- Attack vector Local Needs local access to the machine
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required Low Attacker needs a basic user account
- User interaction None No victim action needed
- Scope Changed Impact crosses a security authority boundary
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculatorReferences
- cisa.gov · icsa-26-183-01 us government resource NVD
- github.com · icsa-26-183-01.json vendor advisory NVD
- cve.org · CVERecord vdb entry
- tenable.com · CVE-2026-38056 third party advisory vdb entry
- cvefeed.io · CVE-2026-38056 third party advisory vdb entry
- euvd.enisa.europa.eu · EUVD-2026-76127 vdb entry
- cveawg.mitre.org · CVE-2026-38056
- support.idirect.net NVD