
Attackers exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE-2026-38059, CVE-2026-38057) to access sensitive device info and trigger system reboots. Campaign demonstrates how satellite infrastructure vulnerabilities enable both information theft and service disruption. #CloudSecurity :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/st-engineering-idirect-iq-series-terminals-2026-cve-2026-38059-cve-2026-38057
Post summary
Attackers have actively exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE‑2026‑38059, CVE‑2026‑38057), enabling information theft and service disruption via device reboots.
