---
id: CVE-2026-38056
title: >-
  A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT
  terminal running firmware 23.0.1.0
summary: >-
  A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT
  terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem
  deployed across oil and gas, maritime, defense, and remote infrastructure as
  the pri…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: ST Engineering iDirect
product: Evolution iQ‑Series terminals
affected:
  - evolution_iq_series_terminals <= 4.5.2.1
  - 3315-series_terminals <= 4.5.2.1
  - 9-series_terminals <= 4.5.2.1
published: '2026-09-11'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:35:03.750'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-38056'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-183-01.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://support.idirect.net'
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-01'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
  - cve.org
epss: 0.00152
epssPercentile: 0.03647
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-11T15:02:31.983672Z'
ingestedAt: '2026-09-11T18:53:56.564Z'
---

## Overview

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
