CVE-2026-94216 Details
Description
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. Executing a manipulation of the argument Success can lead to open redirect. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing open redirect has been identified in ST Engineering iDirect Evolution and Velocity WebServer components, specifically in versions through 20260717. The issue arises in the HTTP Header Handler, within the authorize function of the webserver component. By manipulating the Success argument, an attacker can redirect users to external sites. This vulnerability can be exploited remotely and has been publicly disclosed.
It is recommended to validate the 'success' parameter to only allow internal relative paths. Additionally, the application should filter out control characters before writing HTTP headers.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/IDIRECT-WEBSERVER-CRLF-OPENREDIRECT-001-vulndb.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-94216 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/894247 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408071 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408071/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ST Engineering iDirect Evolution | >= 14.0.3, <= 21.0.3.3 |
CPE
Remediation
| |
| ST Engineering iDirect Velocity WebServer | >= 1.6.1.8, <= 3.3.2.3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion