Search

Find a vulnerability

Search criteria

    4 vulnerabilities found for Evolution by ST Engineering iDirect

    CVE-2026-94216 (GCVE-0-2026-94216)

    Vulnerability from nvd – Published: 2026-09-21 12:45 – Updated: 2026-09-30 19:05
    VLAI
    Title
    ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting
    Summary
    A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The validated environment is an EOL X7 (or an un-modelled legacy Evolution 21.x), and current supported releases (X10, X11, Velocity 5.x+) have no validated evidence of impact.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 15:19 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/408071 vdb-entrytechnical-description
    https://vuldb.com/vuln/408071/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94216 third-party-advisory
    https://vuldb.com/submit/894247 third-party-advisory
    https://github.com/dxz0069/WAVLINK-WN530H4-Comman… exploit
    Impacted products
    Vendor Product Version
    ST Engineering iDirect Evolution Affected: n/a
        cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    ST Engineering iDirect Velocity WebServer Evolution Affected: n/a
        cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94216",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T15:19:28.405250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T15:19:48.835Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Request Handler"
              ],
              "product": "Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Request Handler"
              ],
              "product": "Velocity WebServer Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ST4R0003 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The validated environment is an EOL X7 (or an un-modelled legacy Evolution 21.x), and current supported releases (X10, X11, Velocity 5.x+) have no validated evidence of impact."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-113",
                  "description": "HTTP Response Splitting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CRLF Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:05:43.119Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-408071 | ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/408071"
            },
            {
              "name": "VDB-408071 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/408071/cti"
            },
            {
              "name": "CVE-2026-94216 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94216"
            },
            {
              "name": "Submit #894247 | ST Engineering iDirect Evolution/Velocity WebServer Evolution 14.0.3-21.0.3.3; Velocity 1.6.1.8-3.3.2.3 HTTP Response Header Injection / Open Redirect",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/894247"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/IDIRECT-WEBSERVER-CRLF-OPENREDIRECT-001-vulndb.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-21T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-30T20:40:11.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94216",
        "datePublished": "2026-09-21T12:45:08.228Z",
        "dateReserved": "2026-09-21T05:54:34.319Z",
        "dateUpdated": "2026-09-30T19:05:43.119Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94214 (GCVE-0-2026-94214)

    Vulnerability from nvd – Published: 2026-09-21 12:15 – Updated: 2026-09-30 19:05
    VLAI
    Title
    ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect
    Summary
    A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 13:21 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/408070 vdb-entrytechnical-description
    https://vuldb.com/vuln/408070/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94214 third-party-advisory
    https://vuldb.com/submit/894245 third-party-advisory
    https://github.com/dxz0069/WAVLINK-WN530H4-Comman… exploit
    Impacted products
    Vendor Product Version
    ST Engineering iDirect Evolution Affected: 20260717
        cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    ST Engineering iDirect Velocity WebServer Evolution Affected: 20260717
        cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94214",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T13:21:49.530410Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T13:21:59.523Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Location Header Handler"
              ],
              "product": "Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "20260717"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Location Header Handler"
              ],
              "product": "Velocity WebServer Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "20260717"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ST4R0003 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "Open Redirect",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:05:23.080Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-408070 | ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/408070"
            },
            {
              "name": "VDB-408070 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/408070/cti"
            },
            {
              "name": "CVE-2026-94214 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94214"
            },
            {
              "name": "Submit #894245 | ST Engineering iDirect Evolution/Velocity WebServer same 7 Host Header Injection / Open Redirect",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/894245"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/IDIRECT-WEBSERVER-HOST-REDIRECT-002-vulndb.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-21T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-30T20:23:49.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94214",
        "datePublished": "2026-09-21T12:15:08.559Z",
        "dateReserved": "2026-09-21T05:52:16.238Z",
        "dateUpdated": "2026-09-30T19:05:23.080Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94216 (GCVE-0-2026-94216)

    Vulnerability from cvelistv5 – Published: 2026-09-21 12:45 – Updated: 2026-09-30 19:05
    VLAI
    Title
    ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting
    Summary
    A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The validated environment is an EOL X7 (or an un-modelled legacy Evolution 21.x), and current supported releases (X10, X11, Velocity 5.x+) have no validated evidence of impact.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-21 15:19 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/408071 vdb-entrytechnical-description
    https://vuldb.com/vuln/408071/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94216 third-party-advisory
    https://vuldb.com/submit/894247 third-party-advisory
    https://github.com/dxz0069/WAVLINK-WN530H4-Comman… exploit
    Impacted products
    Vendor Product Version
    ST Engineering iDirect Evolution Affected: n/a
        cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    ST Engineering iDirect Velocity WebServer Evolution Affected: n/a
        cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94216",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-21T15:19:28.405250Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-21T15:19:48.835Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Request Handler"
              ],
              "product": "Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "HTTP Request Handler"
              ],
              "product": "Velocity WebServer Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ST4R0003 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. The validated environment is an EOL X7 (or an un-modelled legacy Evolution 21.x), and current supported releases (X10, X11, Velocity 5.x+) have no validated evidence of impact."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-113",
                  "description": "HTTP Response Splitting",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-93",
                  "description": "CRLF Injection",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:05:43.119Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-408071 | ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/408071"
            },
            {
              "name": "VDB-408071 | CTI Indicators (IOB, IOC, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/408071/cti"
            },
            {
              "name": "CVE-2026-94216 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94216"
            },
            {
              "name": "Submit #894247 | ST Engineering iDirect Evolution/Velocity WebServer Evolution 14.0.3-21.0.3.3; Velocity 1.6.1.8-3.3.2.3 HTTP Response Header Injection / Open Redirect",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/894247"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/IDIRECT-WEBSERVER-CRLF-OPENREDIRECT-001-vulndb.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-21T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-30T20:40:11.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution HTTP Request authorize response splitting",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94216",
        "datePublished": "2026-09-21T12:45:08.228Z",
        "dateReserved": "2026-09-21T05:54:34.319Z",
        "dateUpdated": "2026-09-30T19:05:43.119Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-94214 (GCVE-0-2026-94214)

    Vulnerability from cvelistv5 – Published: 2026-09-21 12:15 – Updated: 2026-09-30 19:05
    VLAI
    Title
    ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect
    Summary
    A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-24 13:21 UTC
    CWE
    References
    URL Tags
    https://vuldb.com/vuln/408070 vdb-entrytechnical-description
    https://vuldb.com/vuln/408070/cti signaturepermissions-required
    https://vuldb.com/cve/CVE-2026-94214 third-party-advisory
    https://vuldb.com/submit/894245 third-party-advisory
    https://github.com/dxz0069/WAVLINK-WN530H4-Comman… exploit
    Impacted products
    Vendor Product Version
    ST Engineering iDirect Evolution Affected: 20260717
        cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    ST Engineering iDirect Velocity WebServer Evolution Affected: 20260717
        cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-94214",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-24T13:21:49.530410Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-24T13:21:59.523Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Location Header Handler"
              ],
              "product": "Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "20260717"
                }
              ]
            },
            {
              "cpes": [
                "cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*"
              ],
              "modules": [
                "Location Header Handler"
              ],
              "product": "Velocity WebServer Evolution",
              "vendor": "ST Engineering iDirect",
              "versions": [
                {
                  "status": "affected",
                  "version": "20260717"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "ST4R0003 (VulDB User)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
                "version": "4.0"
              }
            },
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 5,
                "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "Open Redirect",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-30T19:05:23.080Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "name": "VDB-408070 | ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect",
              "tags": [
                "vdb-entry",
                "technical-description"
              ],
              "url": "https://vuldb.com/vuln/408070"
            },
            {
              "name": "VDB-408070 | CTI Indicators (IOB, IOC, TTP, IOA)",
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/vuln/408070/cti"
            },
            {
              "name": "CVE-2026-94214 | CVE Analysis and Report",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/cve/CVE-2026-94214"
            },
            {
              "name": "Submit #894245 | ST Engineering iDirect Evolution/Velocity WebServer same 7 Host Header Injection / Open Redirect",
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://vuldb.com/submit/894245"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/dxz0069/WAVLINK-WN530H4-Command-Injection-in-set_add_routing/blob/main/IDIRECT-WEBSERVER-HOST-REDIRECT-002-vulndb.md"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-09-21T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2026-09-21T02:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2026-09-30T20:23:49.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect",
          "x_generator": [
            "VulDB PVTS v202609"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2026-94214",
        "datePublished": "2026-09-21T12:15:08.559Z",
        "dateReserved": "2026-09-21T05:52:16.238Z",
        "dateUpdated": "2026-09-30T19:05:23.080Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }