CVE-2026-38057Active Exploitation

LOWCVSS 7.0 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Active Exploitation · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE-2026-38059, CVE-2026-38057) to access sensitive device info and trigger system reboots. Campaign demonstrates how satellite infrastructure vulnerabilities enable both information theft and service disruption. #CloudSecurity :link: Full TRC analysis: https://aviatrix.ai/threat-research-center/st-engineering-idirect-iq-series-terminals-2026-cve-2026-38059-cve-2026-38057

    Post summary

    Attackers have actively exploited unauthenticated API endpoints in ST Engineering iDirect terminals (CVE-2026-38059, CVE-2026-38057) to steal data and reboot devices, demonstrating real‑world use of these vulnerabilities.

    0000051
    1.9K followersView on X

Explore more