VulnSea

ST Engineering iDirect has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: Evolution iQ‑Series terminals (4), Evolution (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.8
Publish → KEV
Last 90 days
6 prev 0

Products

  • Evolution iQ‑Series terminals 4
  • Evolution 2
Follow ST Engineering iDirect:RSS feedSave a search →Embed badge ↗
6
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

ST Engineering iDirect vulnerabilities

CVEs affecting ST Engineering iDirect, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-94216Medium· 4.3PoC
today

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…

TwilightST Engineering iDirect · Evolutionvia NVD
CVE-2026-94214Medium· 4.3
today

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…

SunlitST Engineering iDirect · Evolutionvia NVD
CVE-2026-38058High· 8.1
1w ago

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with va…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.34%via NVD
CVE-2026-38056High· 8.8
1w ago

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the pri…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.10%via NVD
CVE-2026-38059High· 7.5
2mo ago

ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Term…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.59%via CVEORG
CVE-2026-38057High· 8.1
2mo ago

ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…

TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.31%via CVEORG
ST Engineering iDirect vulnerabilities (CVEs) · VulnSea