iDirect satellite terminals hit with high-severity API and reboot flaws
CISA has issued a security advisory for ST Engineering iDirect iQ-Series satellite terminals to address high-severity API vulnerabilities. The flaws, which allow for unauthorized device identification and forced reboots, affect enterprise and mobility satellite modems and require an update to firmware version 4.5.2.2 or newer.
Key Takeaways
- CVE-2026-38059 allows unauthenticated attackers to extract Device IDs and Terminal Private Keys used for network authentication.
- CVE-2026-38057 enables CSRF attacks on the reboot endpoint, allowing remote actors to trigger connection-breaking hardware resets.
- Affected hardware includes Evolution iQ-Series, 3315-Series, and 9-Series terminals running software version 4.5.2.1 or earlier.
- ST Engineering iDirect has released a mandatory fix in firmware version 4.5.2.2, available via its central support portal.
Why It Matters
These vulnerabilities target the industrial-grade management plane of satellite backhaul, where hardware is often deployed in remote, unmonitored locations. By exposing unique network identifiers and enabling forced reboots, the flaws move beyond simple data leaks to threaten critical link availability for maritime, energy, and defense operators. This advisory highlights a recurring friction point: as satellite hardware adopts modern REST APIs for remote orchestration, it inherits standard web security risks like CSRF that can compromise specialized infrastructure. Operators should watch for unplanned reboot logs and audit the reachability of administrative interfaces to satisfy increasing zero-trust regulatory requirements for critical space-ground links.
Additional Context
The iDirect advisory arrives as the satellite industry moves aggressively toward standardized, high-capacity architectures for 5G and OTT delivery. In March 2026, ST Engineering iDirect demonstrated a native 5G NR-NTN (Non-Terrestrial Network) connectivity solution at the Satellite 2026 Conference, integrating satellite modems directly into 5G core networks. This push for interoperability, per ST Engineering iDirect, intends to accelerate innovation and simplify roaming. However, as terminals like the iQ-Series become deeper extensions of the terrestrial 5G stack, they also become higher-priority targets for attackers seeking to disrupt backhaul for mobile operators and enterprises. Historically, iDirect has faced similar security hurdles; per NIST and the NVD, the company’s NTC series modems were previously flagged in January 2025 for OS command injection vulnerabilities in their web administration interfaces. While those older flaws were localized to Linux and PowerPC-based systems, the current API vulnerabilities across the broader iQ-Series suggest a persistent challenge in securing management-plane web services. Beyond specific vendor hardware, the broader market is under pressure. Strategic Market Research reported in 2024 that cyber-hardened satellite architecture is now a critical driver, with more than 52% of new defense-oriented satellite constellations expected to integrate dedicated cybersecurity orchestration by 2026. This trend reflects a shift from viewing satellite terminals as simple 'plumbing' to treating them as complex edge nodes that require the same identity-first security and zero-trust monitoring as enterprise servers. CISA and the FBI have consistently urged SATCOM owners to enforce the principle of least privilege and implement independent encryption across links, noting that successful intrusions into satellite networks can grant attackers a foothold in downstream customer environments.
Read full article at techscurrent.com
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source