CISA’s advisory on ST Engineering iDirect iQ-Series satellite terminals highlights the operational risk created when device-management interfaces expose sensitive information or permit unauthorized actions.

The vulnerabilities affect Evolution iQ-Series, 3315-Series, and 9-Series terminals running software version 4.5.2.1 or earlier.

CVE-2026-38059 allows an unauthenticated attacker with network access to retrieve device information through exposed API endpoints. The disclosed information may include serial numbers, device identifiers, MAC addresses, firmware versions, and authentication-related identifiers that could support reconnaissance or terminal impersonation attempts.

CVE-2026-38057 is a cross-site request forgery vulnerability that can allow an attacker to trick an authenticated administrator’s browser into rebooting the terminal. Repeated exploitation could cause satellite link disruption and sustained denial of service.

Organizations should upgrade affected terminals to version 4.5.2.2 or later. Management interfaces and administrative APIs should be restricted to trusted networks, VPN connections, or approved source addresses and should never be directly exposed to the public internet.

Security teams should also monitor for unusual API requests, unexpected device reboots, configuration changes, and access from unfamiliar systems.

The key lesson is that information disclosure and forced reboot vulnerabilities can have serious consequences in satellite communications. A flaw that appears limited on an ordinary device may disrupt connectivity, reveal network intelligence, or affect critical services when it exists at a remote communications endpoint.


View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057) CVSS Vendor Equipment Vulnerabilities v3 8.1 ST Engineering iDirect ST Engineering iDirect iQ-Series Terminals Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF) Background Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-38059 The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance. View CVE Details Affected Products ST Engineering iDirect iQ-Series Terminals Vendor: ST Enginee

Source: ST Engineering iDirect iQ-Series Terminals via CISA Advisories — published 02 Jul 2026.