VulnSea

9-series_terminals vulnerabilities

CVEs whose affected-version data names the 9-series_terminals package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-38058High· 8.1
1w ago

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with va…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.34%via NVD
CVE-2026-38056High· 8.8
1w ago

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the pri…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.10%via NVD
CVE-2026-38059High· 7.5
2mo ago

ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Term…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.59%via CVEORG
CVE-2026-38057High· 8.1
2mo ago

ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.31%via CVEORG
9-series_terminals vulnerabilities (CVEs) · VulnSea