CVE-2026-38057: ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery

Published Jul 10, 2026
·
Updated

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.

Affected Software

1 affected component
ST Engineering iDirect iQ200 iQ-Series Terminal

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ST Engineering iDirect iQ-Series Terminals to a version that resolves this vulnerability.

    Fixed in 4.5.3.0
  2. Configuration

    Update configuration so the session cookie includes the SameSite attribute to prevent cross-site POST requests to /api/reboot.

    iDirect iQ-Series Terminals (web/session cookies) SameSite attribute on session cookie = set
  3. Configuration

    Ensure the iQ200 validates CSRF tokens on state-changing API endpoints after authentication (including /api/reboot).

    iDirect iQ200 CSRF token validation for state-changing API endpoints = enabled
  4. Compensating control

    Restrict management interfaces and administrative APIs to trusted networks only (e.g., VPN and/or ACLs) instead of exposing them to the public internet.

  5. Compensating control

    Monitor API activity for anomalies and detect unexpected device reboots to identify repeated denial-of-service attempts.

Event History

Jul 10, 2026
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-38057?

The severity of CVE-2026-38057 is rated high with a score of 7.

2

How do I fix CVE-2026-38057?

To fix CVE-2026-38057, ensure that CSRF tokens are validated on all state-changing API endpoints and consider implementing SameSite attributes for session cookies.

3

What type of vulnerability is CVE-2026-38057?

CVE-2026-38057 is a Cross-Site Request Forgery (CSRF) vulnerability.

4

What software is affected by CVE-2026-38057?

CVE-2026-38057 affects the ST Engineering iDirect iQ200 iQ-Series Terminal.

5

How can an attacker exploit CVE-2026-38057?

An attacker can exploit CVE-2026-38057 by hosting a malicious web page that manipulates the affected API endpoint when visited by an authenticated user.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203