Junglewise Threat Intelligence

CVE-2026-38057: ST Engineering iDirect iQ-Series CSRF in reboot API

CVE-2026-38057 · Severity: high · CVSS 8.1 · Published 2026-07-10

Executive brief

ST Engineering iDirect satellite terminals are vulnerable to a security flaw that allows an attacker to force the device to reboot. By tricking an authenticated administrator into visiting a malicious website, the attacker can remotely trigger a restart, leading to an immediate loss of satellite connectivity. Repeated attacks can be used to keep the device offline indefinitely, disrupting critical communications.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the REST API of iDirect iQ-Series terminals (Evolution, 3315, and 9-Series). The /api/reboot endpoint fails to validate CSRF tokens and relies on session cookies that lack the SameSite attribute. An attacker can exploit this by hosting a malicious webpage that sends a cross-site POST request to the affected endpoint. If an authenticated administrator visits the malicious page, the device will execute the reboot command. This results in a loss of satellite link, and persistent exploitation can lead to a sustained denial-of-service (DoS). The issue is resolved in firmware version 4.5.2.2.

Affected products

  • ST Engineering iDirect Evolution iQ-Series terminals <= 4.5.2.1
  • ST Engineering iDirect 3315-Series terminals <= 4.5.2.1
  • ST Engineering iDirect 9-Series terminals <= 4.5.2.1

Timeline

  • 2026-07-02: advisory: Initial CISA advisory publication
  • 2026-07-10: disclosed: NVD publication date
  • 2026-07-02: patched: Firmware version 4.5.2.2 released to address the issue

References

Related threats