ST Engineering iDirect iQ-Series Terminals

Plan PatchCVSS 8.1ICS-CERT ICSA-26-183-01Jul 2, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

ST Engineering iDirect iQ-Series satellite communication terminals versions 4.5.2.1 and earlier contain authentication and authorization vulnerabilities (CWE-306, CWE-352). These vulnerabilities allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. Affected products include Evolution iQ-Series, 3315-Series, and 9-Series terminals.

What this means
What could happen
An attacker could gain unauthorized access to satellite terminal device information or cause the terminal to stop responding to commands, disrupting communications or data services dependent on these satellite links.
Who's at risk
Organizations using ST Engineering iDirect satellite communication terminals, including those in telecommunications, maritime operations, remote site connectivity, and backup communications for utilities and critical infrastructure. Specifically affects Evolution iQ-Series, 3315-Series, and 9-Series terminal models.
How it could be exploited
An attacker on the network sends a specially crafted request to the terminal's management interface without authentication. The terminal processes the request and either exposes sensitive device information or stops responding. No user interaction is required for the denial-of-service variant.
Prerequisites
  • Network access to the terminal's management interface (default or configured port)
  • No valid credentials required for exploitation
remotely exploitableno authentication requiredlow complexityhigh CVSS score (8.1)
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (3)
3 pending
ProductAffected VersionsFix Status
Evolution iQ‑Series terminals≤ 4.5.2.1No fix yet
3315‑Series terminals≤ 4.5.2.1No fix yet
9‑Series terminals≤ 4.5.2.1No fix yet
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict access to terminal management interfaces using firewall rules or ACLs to trusted networks only (engineering VPN, management subnets)
HARDENINGDo not expose administrative APIs to the public internet; use private networks or VPN for all terminal management
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate all Evolution iQ, 3315-Series, and 9-Series terminals to firmware version 4.5.2.2 or newer
HARDENINGEnforce strong authentication (complex passwords, multi-factor authentication where supported) on all terminal administrative accounts
API: /api/v1/advisories/542de46c-547f-42ae-96e8-0b995d22c4bb

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.