Description
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Patch when available
AI Analysis

Impact

The vulnerability in ST Engineering iDirect Evolution and Velocity WebServer Evolution allows a remote attacker to manipulate the Host header to trigger an open redirect to arbitrary URLs, as detailed in the updated CVE description. This remains a CWE‑601 flaw that can facilitate phishing or social engineering attacks.

Affected Systems

Affected systems are the ST Engineering iDirect Evolution and Velocity WebServer Evolution platforms, all releases up to and including 20260717. The flaw resides in a component referred to as the Location Header Handler, and no precise version numbers are listed beyond the cut‑off date. Organizations running these products should verify whether their installed versions fall within this affected range.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate impact and the EPSS score of 0.00462 shows a very low probability of exploitation, though the presence of a public exploit increases the risk. The vulnerability is not yet listed in the CISA KEV catalog, suggesting it is not known to be actively exploited, yet the public exploit indicates potential for misuse. Since the attack can be performed remotely by altering a legitimate request, the risk remains unless mitigated or patched.

Generated by OpenCVE AI on October 1, 2026 at 21:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and install vendor patches that close the open‑redirect flaw in the Location Header Handler.
  • Implement input validation for the Host header used in redirect responses, ensuring only trusted hostnames are accepted and rejecting any other values.
  • If the redirect functionality is not required, disable the redirect feature or block access to it from external sources.

Generated by OpenCVE AI on October 1, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

Wed, 30 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect ST Engineering iDirect Evolution/Velocity WebServer Evolution Location Header redirect

Thu, 24 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect
First Time appeared St Engineering Idirect
St Engineering Idirect evolution
St Engineering Idirect velocity Webserver Evolution
Weaknesses CWE-601
CPEs cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
Vendors & Products St Engineering Idirect
St Engineering Idirect evolution
St Engineering Idirect velocity Webserver Evolution
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

St Engineering Idirect Evolution Velocity Webserver Evolution
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T19:05:23.080Z

Reserved: 2026-09-21T05:52:16.238Z

Link: CVE-2026-94214

cve-icon Vulnrichment

Updated: 2026-09-24T13:21:55.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T13:17:12.170

Modified: 2026-09-30T19:16:41.720

Link: CVE-2026-94214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:45:06Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')