
Attackers exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE-2026-38059, CVE-2026-38057) to access sensitive device info and trigger system reboots. Campaign demonstrates how satellite infrastructure vulnerabilities enable both information theft and service disruption. #CloudSecurity :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/st-engineering-idirect-iq-series-terminals-2026-cve-2026-38059-cve-2026-38057
Post summary
Attackers have actively exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE-2026-38059, CVE-2026-38057) to steal data and reboot devices, demonstrating real‑world use of these vulnerabilities.
