SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-38056

HIGH · CVSS 8.8 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

A local privilege escalation vulnerability in the iDirect iQ200 VSAT terminal allows attackers to gain full administrative control using a pre-configured low-privilege account intended for maintenance. This poses a significant risk to critical infrastructure sectors, including oil and gas, maritime, and defense, where the device serves as the primary communications link. Organizations utilizing this terminal should prioritize immediate remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-38056
Severity
HIGH
CVSS
8.8
EPSS
0.10%

Original NVD Description

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.