Answer in brief
CVE-2026-38057 records a High severity (CVSS 8.1) vulnerability in ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery. The current sources do not mark it as known exploited. The current feed maps ST Engineering iDirect/3315-Series (generic), ST Engineering iDirect/9-Series Terminals (generic), ST Engineering iDirect/Evolution iQ‑Series terminals (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ST Engineering iDirect/3315-Series (generic), ST Engineering iDirect/9-Series Terminals (generic), ST Engineering iDirect/Evolution iQ‑Series terminals (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ST Engineering iDirect/3315-Seriesgeneric | 0 | Not reported |
| ST Engineering iDirect/9-Series Terminalsgeneric | 0 | Not reported |
| ST Engineering iDirect/Evolution iQ‑Series terminalsgeneric | 0 | Not reported |
Published upstream
Jul 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 10, 2026
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-38057 records a High severity (CVSS 8.1) vulnerability in ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery. The current sources do not mark it as known exploited. The current feed maps ST Engineering iDirect/3315-Series (generic), ST Engineering iDirect/9-Series Terminals (generic), ST Engineering iDirect/Evolution iQ‑Series terminals (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ST Engineering iDirect/3315-Series (generic), ST Engineering iDirect/9-Series Terminals (generic), ST Engineering iDirect/Evolution iQ‑Series terminals (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ST Engineering iDirect/3315-Seriesgeneric | 0 | Not reported |
| ST Engineering iDirect/9-Series Terminalsgeneric | 0 | Not reported |
| ST Engineering iDirect/Evolution iQ‑Series terminalsgeneric | 0 | Not reported |
Published upstream
Jul 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 10, 2026
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
Quoted source text, attributed separately from HOL analysis.