The Cybersecurity and Infrastructure Security Agency has flagged two high-severity vulnerabilities in ST Engineering iDirect iQ-Series satellite terminals, warning that attackers can exploit the flaws to impersonate devices on satellite networks and harvest sensitive operational data.
CISA’s advisory, published July 2, details a missing authentication flaw tracked as CVE-2026-38059 with a CVSS score of 8.1. The iDirect iQ200 exposes REST API endpoints including /api/identity and /api/ without any authentication checks. An unauthenticated attacker with network access can extract the device serial number, Device ID, Terminal Private Key identifier, MAC address, and exact firmware version. Both the Device ID and Terminal Private Key are used for satellite network authentication on the iDirect platform, enabling terminal impersonation and broad network reconnaissance.
A second vulnerability, CVE-2026-38057, involves a cross-site request forgery flaw in the same terminal series, allowing attackers to perform unauthorized actions if an authenticated user visits a malicious site.
The affected products span three terminal families: Evolution iQ-Series terminals, 3315-Series terminals, and 9-Series terminals, all running software version 4.5.2.1 or earlier. These terminals are deployed globally across communications, defense industrial base, energy, government services, and transportation sectors. Ahmed Alqahtani of Aramco reported the vulnerabilities.
ST Engineering iDirect has released version 4.5, which addresses both issues. CISA recommends organizations update immediately and restrict network access to terminal management interfaces. Operators should also monitor for unauthorized attempts to query the exposed API endpoints.
The advisory arrives as satellite communications infrastructure faces increasing scrutiny from threat actors and regulators alike. The EU Space Act, introduced in June, proposes mandatory 12-hour cyberattack reporting for satellite operators, and Space ISAC has reported a sharp rise in sector-wide incidents over the past year.