Update to firmware version 4.5.3.0 or newer. Restrict management interfaces to trusted networks (VPN, ACLs). Avoid exposing administrative APIs to the public internet. Enforce strong authentication. Monitor for anomalous API activity and unexpected device reboots. Patches available via iDirect Support Portal.
Quick answers
What is CVE-2026-38056?
Update to firmware version 4.5.3.0 or newer. Restrict management interfaces to trusted networks (VPN, ACLs). Avoid exposing administrative APIs to the public internet. Enforce strong authentication. Monitor for anomalous API activity and unexpected device reboots. Patches available via iDirect Support Portal.
How severe is CVE-2026-38056?
high, CVSS 8.8
Is CVE-2026-38056 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-38056 be mitigated?
Update to firmware version 4.5.3.0 or newer. Restrict management interfaces to trusted networks (VPN, ACLs). Avoid exposing administrative APIs to the public internet. Enforce strong authentication. Monitor for anomalous API activity and unexpected device reboots. Patches available via iDirect Support Portal.
CVSS
8.8
Vendor
ST Engineering iDirect
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
ST Engineering iDirect Evolution iQ-Series terminals, ST Engineering iDirect 3315-Series terminals, ST Engineering iDirect 9-Series terminals
Mitigation
Update to firmware version 4.5.3.0 or newer. Restrict management interfaces to trusted networks (VPN, ACLs). Avoid exposing administrative APIs to the public internet. Enforce strong authentication. Monitor for anomalous API activity and unexpected device reboots. Patches available via iDirect Support Portal.
CISA has published an advisory (ICSA-26-183-01) covering four vulnerabilities in ST Engineering iDirect iQ-Series satellite terminals (Evolution, 3315, and 9-Series). The most severe issues allow unauthenticated attackers to retrieve sensitive device information and cause denial-of-service via cross-site request forgery. Patches are available in firmware version 4.5.3.0.