CVE-2026-38057High· 8.1▾ TwilightThe iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.3%
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
evolution_iq_series_terminals <= 4.5.2.13315-series_terminals <= 4.5.2.19-series_terminals <= 4.5.2.1ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer. Registered users are able to download patches from the iDirect Support Portal: https://support.idirect.net https://support.idirect.net/
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-38058High· 8.1The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts
CVE-2026-38059High· 7.5ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function
CVE-2026-38056High· 8.8A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0
CVE-2026-94216Medium· 4.3A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717
CVE-2026-94214Medium· 4.3A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717
CVE-2017-20120Medium· 4.3A vulnerability classified as problematic was found in TrueConf Server 4.3.7