CVE-2026-38057
ST Engineering iDirect Evolution iQ‑Series terminals, 3315-Series, 9-Series Terminals 취약점
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
- 대응 우선순위
- 점검
- CVSS
- 7
- EPSS
- 0.23% 백분위 13.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.11