PT-2026-89880 · St Engineering Idirect · 3315-Series Terminals+2

·

CVE-2026-38058

·

Publicado

2026-09-11

·

Atualizado

2026-09-11

CVSS v3.1

8.1

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-38058

Produtos afetados

3315-Series Terminals
9-Series Terminals
Evolution Iq‑Series Terminals