Executive brief
ST Engineering's iDirect Evolution and Velocity WebServer Evolution products contain an open redirect vulnerability in their Management Service login functionality. An attacker can manipulate the Host parameter in /login.html to redirect users to arbitrary external websites, enabling phishing attacks and credential theft. The vulnerability affects versions up to 20260717, and the vendor has not responded to disclosure.
Technical details
The Management Service component fails to validate the Host parameter in /login.html, allowing an attacker to inject arbitrary hostnames that redirect users to attacker-controlled sites. This is a network-accessible open redirect vulnerability requiring no authentication; an attacker can craft malicious links to deceive users into visiting phishing pages. While the vulnerability has been publicly disclosed and PoC code exists, there is no confirmed vendor patch available.
Affected products
- ST Engineering iDirect Evolution up to 20260717
- ST Engineering Velocity WebServer Evolution up to 20260717
Timeline
- 2026-09-21: disclosed: Vulnerability publicly disclosed on GitHub