A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0.

Published September 11, 2026 CVE-2026-38056

A built-in technician account can gain administrative control of affected iDirect satellite terminals. The flaw requires local access, but no extra credentials or user action.

Severity
HighCVSS 3.1 · 8.8 · hq.dhs.gov
Fix
Fixed in 4.5.3.0
Affected versions
through 4.5.2.1; through 4.5.2.1; through 4.5.2.1
Weakness
CWE-862Missing Authorization
Affects
Evolution iQ‑Series terminals+2 more
Exploited
Not confirmedNo confirmation recorded
CISA SSVC
No known exploitationAutomatable: no · Technical impact: total
EU ID
EUVD-2026-76127ENISA vulnerability database

How it works

  • The terminal ships with a built-in account for local maintenance and diagnostics.
  • That account supplies the local shell access needed for this flaw.
  • The software fails to enforce the account's intended limits, allowing higher privileges.
  • The retrieved evidence does not identify the exact command or action that triggers this failure.

What to do

If you manage Evolution iQ-Series, 3315-Series, or 9-Series terminals, check whether each runs software 4.5.2.1 or earlier. Treat an iQ200 running firmware 23.0.1.0 as specifically covered by this advisory.

Update affected terminals to software version 4.5.3.0 or newer. Download the update through the iDirect Support Portal. Until updated, restrict management access to trusted networks and keep administrative interfaces off the public internet.

Technical details

Affected software: Evolution iQ‑Series terminalsby ST Engineering iDirect, 3315-Series terminalsby ST Engineering iDirect, 9-Series Terminalsby ST Engineering iDirect

CVE-2026-38056 is a local privilege escalation flaw caused by missing authorization controls. The built-in low-privilege technician account provides the initial shell access, without requiring additional stolen or guessed credentials. CISA lists Evolution iQ-Series, 3315-Series, and 9-Series terminals through 4.5.2.1 as affected. Version 4.5.3.0 is listed as unaffected.

Severity breakdown

  • Attack vector Local Needs local access to the machine
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Changed Impact crosses a security authority boundary
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Open in FIRST.org calculator

References