What a VSAT terminal is, why it keeps showing up in scans, and the checklist every fleet manager should run before the next port call.
VSAT, or very small aperture terminal, is the satellite dish and modem that carries a ship's internet, phone, and increasingly its operational data. The terminal has a management interface, usually a web page served from the modem itself.
That management page is the problem. It sits on a public IP assigned by the satellite operator, and in many installations it ships with default credentials or no authentication at all.
A reachable VSAT web GUI typically exposes: terminal model and firmware, network status and IP addresses, sometimes GPS-derived position, and frequently the ability to reconfigure or reboot the terminal.
An attacker does not need to break in to cause harm. Rebooting terminals across a fleet, or reconfiguring one to route traffic somewhere else, is enough to disrupt operations for days.
1. Enable authentication on every terminal web GUI. This single change removes the most common finding in our scans.
2. Change default credentials at installation. Document the process; make it part of commissioning.
3. Restrict management access by source IP. If the terminal supports ACLs, allow only the operator's shore IPs.
4. Keep firmware current. Terminal vendors patch known CVEs; the fixes only help if they are installed.
5. Scan quarterly. Exposure changes with every port call and firmware update. Make it a recurring item, not a one-off.
A VSAT terminal is not plumbing. It is a network device with a management plane, and it deserves the same discipline as any other asset: inventory, baseline, patch cycle, and regular external review.
An empirical breakdown of the queries and satellite ASN ranges that surface exposed vessels.
Electronic chart display risks explained without jargon: what can go wrong, and what bridge teams should know.
What Port State Control inspections will check, what evidence counts, and how to prepare.
A free Shipcrawler scan will tell you in 24 hours.