CISA issued Update A to advisory ICSA-26-183-01, covering four vulnerabilities in ST Engineering iDirect iQ-series satellite (VSAT) terminals, with CVSS scores up to 8.8 and one flaw rated 9.4 on the CVSS 4.0 scale. The advisory was originally released July 2, 2026.
The flaws include missing authentication on REST API endpoints that expose device identity and cryptographic material, a cross-site request forgery vulnerability that can trigger a remote reboot or denial of service, a local privilege-escalation path via a factory-default low-privilege account, and exposure of password hashes. CISA lists Communications, Defense Industrial Base, Energy, Government and Transportation as affected sectors.
Why it matters: VSAT terminals from vendors like ST Engineering iDirect provide connectivity for maritime vessels, remote energy sites, and defense operations where terrestrial networks are unavailable. Authentication bypasses on internet-facing satellite terminal management interfaces are a persistent, underappreciated risk category for organizations with remote or offshore infrastructure.
Source: CISA ICS Advisory ICSA-26-183-01 (Update A), September 10, 2026.

Leave a Reply