← Knowledge Center
Advisory CVE-2026-38059, CVE-2026-38057

CISA: ST Engineering iDirect iQ-Series Terminals Expose Unauthenticated API Endpoints

CISA published an ICS advisory covering ST Engineering iDirect iQ-Series satellite terminals (Evolution iQ-Series, 3315-Series, and 9-Series, versions <=4.5.2.1). The most notable flaw, CVE-2026-38059, stems from missing authentication on the /api/identity and other REST API endpoints. An unauthenticated attacker with network access can retrieve sensitive device information such as the serial number, Device ID (DID), and Terminal Private Key identifier. A second issue, CVE-2026-38057, involves cross-site request forgery (CSRF), and the advisory carries a CVSS v3 score of 8.1.

From an identity perspective, exposing device identity attributes and private key identifiers without authentication weakens the trust foundation these terminals rely on. Leaked identity material can support device impersonation or targeted follow-on attacks, and the affected equipment is deployed worldwide across communications, defense, energy, government, and transportation sectors.

What to take away: treat any device that leaks identity or key material via unauthenticated APIs as a credential exposure risk. Restrict network access to management interfaces, segment these terminals, and apply vendor fixes to close the authentication gap.

Primary source

CISA Cybersecurity Advisories

Read at cisa.gov ↗

Summary by AD Argus. We publish our own analysis with attribution and a link to the original report; always consult the primary source for authoritative detail.