CVE-2026-38058
Last modified
CVE-2026-38058 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ST Engineering iDirect | Evolution iQ‑Series terminals | <= 4.5.2.1 |
| ST Engineering iDirect | 3315-Series terminals | <= 4.5.2.1 |
| ST Engineering iDirect | 9-Series Terminals | <= 4.5.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-38058?
How severe is CVE-2026-38058?
How do I fix CVE-2026-38058?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3802A vulnerability was determined in Tenda i3 1.0.0.6(2204). Af…8.8
- CVE-2026-3803A vulnerability was identified in Tenda i3 1.0.0.6(2204). Th…8.8
- CVE-2026-3804A security flaw has been discovered in Tenda i3 1.0.0.6(2204…8.8
- CVE-2026-3805When doing a second SMB request to the same host again, curl…7.5
- CVE-2026-38056A local privilege escalation vulnerability exists in the iDi…8.8
- CVE-2026-38057The iDirect iQ200 does not validate CSRF tokens on state-cha…8.1
- CVE-2026-38059The iDirect iQ200 exposes the /api/identity and /api/ REST A…7.5
- CVE-2026-3806A weakness has been identified in SourceCodester/janobe Reso…8.8
- CVE-2026-38060Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38061Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38062Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38063Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
Are you affected by CVE-2026-38058?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
