CVE-2026-38059
Last modified
CVE-2026-38059 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version.
Description
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| ST Engineering iDirect | Evolution iQ‑Series terminals | <= 4.5.2.1 |
| ST Engineering iDirect | 3315-Series | <= 4.5.2.1 |
| ST Engineering iDirect | 9-Series Terminals | <= 4.5.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-38059?
How severe is CVE-2026-38059?
How do I fix CVE-2026-38059?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-3801A vulnerability was found in Tenda i3 1.0.0.6(2204). Affecte…8.8
- CVE-2026-3802A vulnerability was determined in Tenda i3 1.0.0.6(2204). Af…8.8
- CVE-2026-3803A vulnerability was identified in Tenda i3 1.0.0.6(2204). Th…8.8
- CVE-2026-3804A security flaw has been discovered in Tenda i3 1.0.0.6(2204…8.8
- CVE-2026-3805When doing a second SMB request to the same host again, curl…7.5
- CVE-2026-38057The iDirect iQ200 does not validate CSRF tokens on state-cha…8.1
- CVE-2026-3806A weakness has been identified in SourceCodester/janobe Reso…8.8
- CVE-2026-38060Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38061Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38062Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38063Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
- CVE-2026-38064Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Comma…9.8
Are you affected by CVE-2026-38059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
