CVE-2026-38057: St Engineering Idirect 3315-Series Terminals
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
Affected products
- St Engineering Idirect 3315-Series Terminals: up to and including 4.5.2.1
- St Engineering Idirect 9-Series Terminals: up to and including 4.5.2.1
- St Engineering Idirect Evolution Iq‑series Terminals: up to and including 4.5.2.1
Published 2026-07-10. Last modified 2026-09-11.