CVE-2026-38058
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
- Published Sep 11, 2026
- CVSS 8.6 high
- 0.5% chance of exploitation in the next 30 days (EPSS)