Sceawere
Vulnerability Detail
CVE-2026-38056UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
iDirect iQ200 Local Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- ST Engineering iDirect
- Product
- Evolution iQ‑Series terminals
- Attack Type
- CWE-862
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-11T15:17:01.070Z",
"pubdate": "2026-09-11T15:17:01.070Z",
"executiveSummary": "A local privilege escalation vulnerability has been identified in the iDirect iQ200 VSAT terminal, specifically impacting firmware version 23.0.1.0. This flaw allows a pre-configured, low-privilege field technician account to bypass established access control mechanisms and attain administrative control over the terminal.\nThe vulnerability represents a significant security risk, as the iQ200 is frequently deployed as the primary communications gateway for critical infrastructure sectors, including maritime operations, oil and gas, and defense systems. By leveraging the default local user account, an attacker with physical or terminal access can transition from restricted diagnostic privileges to full system administration.\nThe primary risk implication is the potential for complete device compromise, enabling unauthorized configuration changes, persistent backdoor installation, traffic interception, or the disruption of communication services. The exploitation does not require credential brute-forcing, as the vulnerability utilizes the existing, legitimate low-privilege account shipped with the device. This provides a direct path for escalation, significantly lowering the barrier to entry for unauthorized actors aiming to compromise remote, high-value satellite communication assets.",
"technicalDetails": "The vulnerability resides within the privilege management architecture of the iDirect iQ200 firmware 23.0.1.0. The device ecosystem is designed with a tiered access model, utilizing a factory-default low-privilege user account intended for field maintenance, diagnostics, and CLI-based troubleshooting. The flaw stems from an improper implementation of sudo-equivalent rights or a misconfigured setuid/setgid binary that fails to adequately sanitize environmental inputs or validate user context before executing administrative tasks.\nExploitation is initiated by authenticating to the iQ200 terminal using the provided low-privilege technician credentials. Upon establishing a local shell session, the attacker interacts with identified vulnerable components—specifically binaries or scripts with elevated execution context—to trigger an privilege escalation flow. The root cause is likely an insecure handling of user-supplied arguments or environment variables within a component tasked with performing system-level updates or configuration modifications.\nThe attack flow follows a structured methodology: First, the attacker establishes a local interactive session using the pre-configured technician account. Second, the attacker probes for identified binaries or services that exhibit inconsistent privilege dropping or fail to enforce strict UID/GID checks during runtime. Third, by crafting a malicious payload or manipulating input buffers, the attacker exploits the lack of validation in the target function. This forces the component to execute commands with the privileges of the root or administrative user rather than the restricted technician user.\nOnce the privilege boundary is breached, the attacker gains unrestricted access to the underlying Linux-based operating system of the VSAT terminal. This post-exploitation state grants the ability to modify system configurations, alter routing tables, deploy persistent rootkits, or exfiltrate sensitive operational data transmitted over the satellite link. Given the terminal's role as a primary communication gateway, this level of control could facilitate man-in-the-middle attacks or full degradation of the terminal's integrity, potentially affecting the safety and reliability of the remote site being serviced. The vulnerability necessitates a fundamental review of the permission inheritance model within the terminal's firmware to ensure that restricted accounts remain sandboxed and incapable of invoking high-privilege system primitives."
}