ST Engineering iDirect has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 4. The median CVSS is 7.8 (high). None have a confirmed exploitation report. Most affected products: Evolution iQ‑Series terminals (4), Evolution (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.8
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Products
- Evolution iQ‑Series terminals 4
- Evolution 2
Worst active — by depth score
CVE-2026-38056High· 8.8A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.048CVE-2026-38058High· 8.1The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts45CVE-2026-38057High· 8.1ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery45CVE-2026-38059High· 7.5ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function41CVE-2026-94216Medium· 4.3A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 2026071736
ST Engineering iDirect vulnerabilities
CVEs affecting ST Engineering iDirect, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-94216Medium· 4.3PoCA vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…
CVE-2026-94214Medium· 4.3A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…
CVE-2026-38058High· 8.1The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with va…
CVE-2026-38056High· 8.8A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the pri…
CVE-2026-38059High· 7.5ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Term…
CVE-2026-38057High· 8.1ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote att…