Impact
The vulnerability in ST Engineering iDirect Evolution and Velocity WebServer Evolution allows a remote attacker to manipulate the Host header to trigger an open redirect to arbitrary URLs, as detailed in the updated CVE description. This remains a CWE‑601 flaw that can facilitate phishing or social engineering attacks.
Affected Systems
Affected systems are the ST Engineering iDirect Evolution and Velocity WebServer Evolution platforms, all releases up to and including 20260717. The flaw resides in a component referred to as the Location Header Handler, and no precise version numbers are listed beyond the cut‑off date. Organizations running these products should verify whether their installed versions fall within this affected range.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate impact and the EPSS score of 0.00462 shows a very low probability of exploitation, though the presence of a public exploit increases the risk. The vulnerability is not yet listed in the CISA KEV catalog, suggesting it is not known to be actively exploited, yet the public exploit indicates potential for misuse. Since the attack can be performed remotely by altering a legitimate request, the risk remains unless mitigated or patched.
OpenCVE Enrichment