CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ST Engineering iDirect iQ-Series Terminals

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 260

As cited

Copy frozen at (site build).

vulnerabilities

ST Engineering iDirect iQ-Series Terminals

ST Engineering iDirect iQ-Series Terminals contain two critical vulnerabilities affecting Evolution iQ, 3315, and 9-Series terminals in version 4.5.2.1 and earlier. CVE-2026-38059 exposes unauthenticated REST API endpoints that leak sensitive device information including serial numbers and authentication credentials, while CVE-2026-38057 lacks CSRF protection on state-changing endpoints, allowing remote denial-of-service attacks. ST Engineering has released patches in version 4.5.2.2 and recommends immediate updates, along with restricting administrative interfaces to trusted networks.

Why it matters: Organizations using iDirect satellite terminals should patch immediately to version 4.5.2.2; unauthenticated API exposure combined with CSRF flaws enables both reconnaissance and service disruption in critical infrastructure environments.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ST Engineering iDirect iQ-Series Terminals

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ST Engineering iDirect iQ-Series Terminals

ST Engineering iDirect iQ‑Series terminals running firmware version 4.5.2.1 or earlier contain two vulnerabilities: CVE-2026-38059, which leaves the /api/identity and /api/ REST endpoints without authentication, and CVE-2026-38057, which fails to validate CSRF tokens on state‑changing endpoints such as /api/reboot. Exploitation of CVE-2026-38059 lets an unauthenticated attacker with network access retrieve sensitive data including serial number, device ID, terminal private key identifier, MAC address, and firmware version, while CVE-2026-38057 allows an authenticated administrator’s session to be hijacked to trigger a device reboot, causing a denial of service.

Why it matters: Operators of ST Engineering iDirect iQ‑Series terminals with firmware 4.5.2.1 or earlier are exposed to unauthenticated information disclosure and CSRF based reboot attacks; they should update to version 4.5.2.2 or newer and restrict management interfaces to trusted networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

ST Engineering iDirect iQ-Series Terminals

ST Engineering iDirect iQ‑Series terminals running firmware version 4.5.2.1 or earlier contain two vulnerabilities: CVE-2026-38059, which leaves the /api/identity and /api/ REST endpoints without authentication, and CVE-2026-38057, which fails to validate CSRF tokens on state‑changing endpoints such as /api/reboot. Exploitation of CVE-2026-38059 lets an unauthenticated attacker with network access retrieve sensitive data including serial number, device ID, terminal private key identifier, MAC address, and firmware version, while CVE-2026-38057 allows an authenticated administrator’s session to be hijacked to trigger a device reboot, causing a denial of service.

Why it matters: Operators of ST Engineering iDirect iQ‑Series terminals with firmware 4.5.2.1 or earlier are exposed to unauthenticated information disclosure and CSRF based reboot attacks; they should update to version 4.5.2.2 or newer and restrict management interfaces to trusted networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary