CVE-2026-38059 Details
Description
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.
A vulnerability exists in ST Engineering iDirect iQ-Series terminals, specifically in the Evolution, 3315-Series, and 9-Series models, all running version 4.5.2.1 or earlier. The issue arises from the /api/identity and /api/ REST API endpoints being exposed without authentication. This flaw allows an unauthenticated attacker with network access to retrieve sensitive device information, including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication on the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.
Users are advised to update the software to version 4.5.2.2 or newer. Patches are available for download from the iDirect Support Portal. Additionally, management interfaces should be restricted to trusted networks, avoid exposing administrative APIs to the public internet, and strong authentication practices should be enforced. Organizations should monitor for unusual API activity and unexpected device reboots.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |