PT-2026-57166 · Idirect · Iq200

·

CVE-2026-38059

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions iDirect iQ200 (affected versions not specified)
Description The device exposes the '/api/identity' and '/api/' REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information, including the serial number, MAC address, exact firmware version, Device ID (DID), and Terminal Private Key identifier (TPK). The DID and TPK are used for satellite network authentication in the iDirect platform, which could allow for network reconnaissance and terminal impersonation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38059

Affected Products

Iq200