Impact
The vulnerability in ST Engineering iDirect Evolution and Velocity WebServer Evolution occurs in the component Management Service’s /login.html page. By manipulating the Host argument, an attacker can trigger an open redirect, allowing the malicious host to be included in the redirect response. This flaw, classified as CWE‑601, permits a remote adversary to redirect users to arbitrary URLs, potentially enabling phishing or other social‑engineering attacks.
Affected Systems
Affected systems are the ST Engineering iDirect Evolution and Velocity WebServer Evolution platforms, all releases up to and including 20260717. The flaw resides in an unclear part of /login.html within the Management Service, and no precise version numbers are listed beyond the cut‑off date. Organizations running these products should verify whether their installed versions fall within this affected range.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog, suggesting it is not known to be actively exploited, yet the public exploit indicates potential for misuse. Since the attack can be performed remotely by altering a legitimate request, the risk remains unless mitigated or patched.
OpenCVE Enrichment