CVE-2026-38058
Received Received - Intake

iDirect iQ200 VSAT Terminal MD5 Password Hash Exposure

Vulnerability report for CVE-2026-38058, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: ICS-CERT

Description

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-11
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
st_engineering idirect_iq200 4.5.2.2
st_engineering idirect_iq200 From 4.5.2.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-497 The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The iDirect iQ200 VSAT terminal has an endpoint that exposes the full device configuration in JSON format. This includes the SECURITY section, which contains MD5-crypt password hashes for root SSH and web administration accounts. An attacker with valid web credentials can extract these hashes and crack them offline using common hardware.

Detection Guidance

Check if the iDirect iQ200 VSAT terminal endpoint returns device configuration including SECURITY section with MD5-crypt password hashes. Use network scanning tools to identify affected devices and verify if the endpoint is accessible without proper authentication.

Impact Analysis

If exploited, this vulnerability allows unauthorized access to the device as root or web admin. Attackers could gain full control over the VSAT terminal, intercept communications, or use it as a foothold to move laterally within a network. This poses risks to confidentiality, integrity, and availability of satellite communications.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance failures due to inadequate protection of credentials and data, potentially resulting in legal penalties or data breach notifications.

Mitigation Strategies

Restrict access to the endpoint to authorized users only. Update the device firmware to a patched version if available. Rotate all root SSH and web administration account passwords immediately. Disable unnecessary services and enforce strong password policies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-38058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart