CVE-2026-38057: St Engineering Idirect 3315-Series Terminals

High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.

Affected products

Published 2026-07-10. Last modified 2026-09-11.