As cited
Copy frozen at (site build).
vulnerabilities
ST Engineering iDirect iQ-Series Terminals
ST Engineering iDirect iQ-Series Terminals contain two critical vulnerabilities affecting Evolution iQ, 3315, and 9-Series terminals in version 4.5.2.1 and earlier. CVE-2026-38059 exposes unauthenticated REST API endpoints that leak sensitive device information including serial numbers and authentication credentials, while CVE-2026-38057 lacks CSRF protection on state-changing endpoints, allowing remote denial-of-service attacks. ST Engineering has released patches in version 4.5.2.2 and recommends immediate updates, along with restricting administrative interfaces to trusted networks.
Why it matters: Organizations using iDirect satellite terminals should patch immediately to version 4.5.2.2; unauthenticated API exposure combined with CSRF flaws enables both reconnaissance and service disruption in critical infrastructure environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
ST Engineering iDirect iQ-Series Terminals
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
ST Engineering iDirect iQ-Series Terminals
ST Engineering iDirect iQ‑Series terminals running firmware version 4.5.2.1 or earlier contain two vulnerabilities: CVE-2026-38059, which leaves the /api/identity and /api/ REST endpoints without authentication, and CVE-2026-38057, which fails to validate CSRF tokens on state‑changing endpoints such as /api/reboot. Exploitation of CVE-2026-38059 lets an unauthenticated attacker with network access retrieve sensitive data including serial number, device ID, terminal private key identifier, MAC address, and firmware version, while CVE-2026-38057 allows an authenticated administrator’s session to be hijacked to trigger a device reboot, causing a denial of service.
Why it matters: Operators of ST Engineering iDirect iQ‑Series terminals with firmware 4.5.2.1 or earlier are exposed to unauthenticated information disclosure and CSRF based reboot attacks; they should update to version 4.5.2.2 or newer and restrict management interfaces to trusted networks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
ST Engineering iDirect iQ-Series Terminals
ST Engineering iDirect iQ‑Series terminals running firmware version 4.5.2.1 or earlier contain two vulnerabilities: CVE-2026-38059, which leaves the /api/identity and /api/ REST endpoints without authentication, and CVE-2026-38057, which fails to validate CSRF tokens on state‑changing endpoints such as /api/reboot. Exploitation of CVE-2026-38059 lets an unauthenticated attacker with network access retrieve sensitive data including serial number, device ID, terminal private key identifier, MAC address, and firmware version, while CVE-2026-38057 allows an authenticated administrator’s session to be hijacked to trigger a device reboot, causing a denial of service.
Why it matters: Operators of ST Engineering iDirect iQ‑Series terminals with firmware 4.5.2.1 or earlier are exposed to unauthenticated information disclosure and CSRF based reboot attacks; they should update to version 4.5.2.2 or newer and restrict management interfaces to trusted networks.
- Source published
- First seen by Cybersecurity Tracker