Idirect · Iq200 · CVE-2026-38059
**Name of the Vulnerable Software and Affected Versions**
iDirect iQ200 (affected versions not specified)
**Description**
The device exposes the '/api/identity' and '/api/' REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information, including the serial number, MAC address, exact firmware version, Device ID (`DID`), and Terminal Private Key identifier (`TPK`). The `DID` and `TPK` are used for satellite network authentication in the iDirect platform, which could allow for network reconnaissance and terminal impersonation.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.