Four Flaws in the Satellite Terminal on the Roof
CISA has updated its advisory on ST Engineering iDirect iQ-Series terminals, with a missing authorisation scoring 9.4 on CVSS v4 and unauthenticated retrieval of device information. Firmware 4.5.3.0 fixes them.

CISA issued Update A to ICSA-26-183-01 on 10 September, covering four vulnerabilities in ST Engineering iDirect satellite communication terminals — the Evolution iQ-Series, 3315-Series and 9-Series at version 4.5.2.1 and earlier. The advisory was originally released on 2 July. CVE-2026-38056, a missing authorisation, scores 8.8 on CVSS v3.1 and 9.4 on v4.0. CVE-2026-38059, a missing authentication, scores 7.5 and 8.7. CVE-2026-38058, an information exposure, scores 8.1 and 8.6. CVE-2026-38057, a cross-site request forgery, scores 8.1 and 7.0. An unauthenticated attacker with network access can retrieve sensitive device information; the others enable CSRF-induced reboots, local privilege escalation through a pre-configured user account, and password hash exposure. The fix is version 4.5.3.0 or newer, distributed through the iDirect support portal, with mitigations restricting management interfaces to trusted networks and keeping administrative APIs off the internet.
Satellite terminals occupy an unusual position in an industrial estate and it is worth stating plainly: they are the network connection for the sites that have no other one. A VSAT terminal is on the roof of the remote pumping station, the offshore platform, the mine site, the pipeline compressor station, the ship — locations chosen precisely because nothing else reaches them. Compromising the terminal therefore does not just expose the terminal; it exposes the only path in and out of a site that by definition has no second route and, frequently, no one present.
The pre-configured user account cited in the privilege escalation is the finding worth acting on beyond patching. Terminals are commissioned by a service provider rather than by the site that owns them, and the accounts created during that commissioning often survive unexamined for the life of the installation — which means the question "who has credentials on our satellite terminals" has an answer that the site probably does not know. That is worth establishing while the firmware update is being planned.
The update route is the operational difficulty here, as it often is with remote infrastructure. A firmware update delivered over the satellite link is an update delivered over the thing being updated, on a connection with limited bandwidth and, in many contracts, metered data. It also carries the risk that a failed update strands the site's only connectivity. Sites with a service provider managing the terminal should be asking them for a schedule and a rollback plan rather than assuming this will happen; sites managing their own should sequence the campaign so that the most accessible terminals go first, and should confirm they can reach someone physically present at each remote location before beginning.