Space Security News
  • Home
  • News

    Vast recruits Slingshot co-founder to lead defense satellite push

    July 27, 2026

    Commerce department launches voluntary certification for novel space missions

    July 27, 2026
    Sentinel satellite overlooking the Strait of Hormuz shipping lanes

    EU halts Copernicus imagery release near Iran war zone

    July 27, 2026
    Military GPS satellite with encrypted signal beams in orbit

    Air Force seizes control of troubled jam-proof GPS receiver project

    July 27, 2026
  • Features

    Classified Chinese satellite sweeps the geostationary belt for threats

    July 24, 2026

    Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

    July 24, 2026

    Software-defined radios open new attack surface for satellite networks

    July 22, 2026

    GPS jamming wave pushes UK toward self-reliant satellite security

    July 21, 2026
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Reading: Critical satellite terminal flaws enable device impersonation, CISA says
Share
Search
  • Trending:
  • Alliances
  • Cislunar
  • Commercial
  • Communications
  • Cyber
  • Debris
  • Defense
  • Deterrence
  • Intelligence
  • Launch
  • Strategy
  • Surveillance
  • Missile
  • Navigation
  • War
Font ResizerAa
Space Security NewsSpace Security News
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About Us
    • Mission
    • Services
    • Contact Us
Follow US
© 2026 Space Security News. All Rights Reserved.
News

Critical satellite terminal flaws enable device impersonation, CISA says

CISA warns ST Engineering iDirect satellite terminals carry critical API flaws that let attackers impersonate devices on satellite networks.

By
SSN Staff
Last updated: July 19, 2026
2 Min Read
Share

The Cybersecurity and Infrastructure Security Agency has flagged two high-severity vulnerabilities in ST Engineering iDirect iQ-Series satellite terminals, warning that attackers can exploit the flaws to impersonate devices on satellite networks and harvest sensitive operational data.

CISA’s advisory, published July 2, details a missing authentication flaw tracked as CVE-2026-38059 with a CVSS score of 8.1. The iDirect iQ200 exposes REST API endpoints including /api/identity and /api/ without any authentication checks. An unauthenticated attacker with network access can extract the device serial number, Device ID, Terminal Private Key identifier, MAC address, and exact firmware version. Both the Device ID and Terminal Private Key are used for satellite network authentication on the iDirect platform, enabling terminal impersonation and broad network reconnaissance.

A second vulnerability, CVE-2026-38057, involves a cross-site request forgery flaw in the same terminal series, allowing attackers to perform unauthorized actions if an authenticated user visits a malicious site.

The affected products span three terminal families: Evolution iQ-Series terminals, 3315-Series terminals, and 9-Series terminals, all running software version 4.5.2.1 or earlier. These terminals are deployed globally across communications, defense industrial base, energy, government services, and transportation sectors. Ahmed Alqahtani of Aramco reported the vulnerabilities.

ST Engineering iDirect has released version 4.5, which addresses both issues. CISA recommends organizations update immediately and restrict network access to terminal management interfaces. Operators should also monitor for unauthorized attempts to query the exposed API endpoints.

The advisory arrives as satellite communications infrastructure faces increasing scrutiny from threat actors and regulators alike. The EU Space Act, introduced in June, proposes mandatory 12-hour cyberattack reporting for satellite operators, and Space ISAC has reported a sharp rise in sector-wide incidents over the past year.

TAGGED:API vulnerabilityCISAcritical infrastructureCVE-2026-38057CVE-2026-38059satellite securitysatellite terminalsST Engineering iDirect
SOURCES:CISATechsCurrentZero Day Initiative

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print

LATEST NEWS

Vast recruits Slingshot co-founder to lead defense satellite push

News
July 27, 2026

Commerce department launches voluntary certification for novel space missions

The Office of Space Commerce rolls out a voluntary certification system for novel space activities…

July 27, 2026
Sentinel satellite overlooking the Strait of Hormuz shipping lanes

EU halts Copernicus imagery release near Iran war zone

The EU imposed a 24-hour restriction on Sentinel satellite imagery of the Gulf of Oman…

July 27, 2026
Military GPS satellite with encrypted signal beams in orbit

Air Force seizes control of troubled jam-proof GPS receiver project

The Air Force absorbed the Pentagon's M-code GPS receiver program from the Space Force after…

July 27, 2026

YOU MAY ALSO LIKE

IEEE approves the first international space cybersecurity design standard

The IEEE P3536 standard gives satellite manufacturers a technical framework for building cybersecurity into space systems at the design stage…

Emerging Threats & Tech
July 17, 2026

Japan’s JAXA tests reusable rocket RV-X in milestone for space infrastructure

JAXA's RV-X reusable rocket test flight strengthens Japan's independent space access and launch infrastructure security.

News
July 24, 2026

Space Force delivers over $500 million in rapid technology awards

The Space Force awarded over $500 million in rapid prototyping contracts to commercial companies developing next-generation space technologies.

Emerging Threats & TechNewsSatellite Security
July 18, 2026

Senators question Space Force legal readiness for future space warfare

Lawmakers pressed Space Force leaders on whether the service has adequate legal expertise to operate effectively in increasingly contested space…

NewsSatellite SecurityThreat Actors & Incidents
July 18, 2026

Breaking developments in space and cybersecurity, decoded for the modern defense and technology landscape.

Follow us: 

  • News
  • Features
  • Spotlight
  • Events
  • About Us
  • Mission
  • Services
  • Contact Us
Copyright © 2026 Space Security News. All Rights Reserved.
Privacy Policy | Legal
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?