CVE-2026-38057 Details
Description
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
A cross-site request forgery (CSRF) vulnerability has been identified in the ST Engineering iDirect iQ200 terminals, specifically in versions through 4.5.2.1. The vulnerability arises because the device does not properly validate CSRF tokens on state-changing API endpoints after authentication. The issue is present in the '/api/reboot' endpoint, which accepts POST requests authenticated only by a session cookie that lacks the SameSite attribute. This flaw allows remote attackers to host malicious web pages that, when visited by authenticated administrators, automatically send cross-site POST requests. Such actions can trigger an immediate device reboot, causing a loss of satellite link connectivity. Furthermore, repeated exploitation can create a sustained denial-of-service condition.
Users are advised to update the software to version 4.5.2.2 or newer. Patches are available for download from the iDirect Support Portal. Additionally, management interfaces should be restricted to trusted networks, administrative APIs should not be exposed to the public internet, and strong authentication practices should be enforced. Monitoring for unusual API activity and unexpected device reboots is also recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | [email protected] |
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |