Description
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Open Redirect
Action: Patch when available
AI Analysis

Impact

The vulnerability in ST Engineering iDirect Evolution and Velocity WebServer Evolution occurs in the component Management Service’s /login.html page. By manipulating the Host argument, an attacker can trigger an open redirect, allowing the malicious host to be included in the redirect response. This flaw, classified as CWE‑601, permits a remote adversary to redirect users to arbitrary URLs, potentially enabling phishing or other social‑engineering attacks.

Affected Systems

Affected systems are the ST Engineering iDirect Evolution and Velocity WebServer Evolution platforms, all releases up to and including 20260717. The flaw resides in an unclear part of /login.html within the Management Service, and no precise version numbers are listed beyond the cut‑off date. Organizations running these products should verify whether their installed versions fall within this affected range.

Risk and Exploitability

The CVSS base score of 5.3 indicates a moderate impact and the EPSS score is not available. The vulnerability is not yet listed in the CISA KEV catalog, suggesting it is not known to be actively exploited, yet the public exploit indicates potential for misuse. Since the attack can be performed remotely by altering a legitimate request, the risk remains unless mitigated or patched.

Generated by OpenCVE AI on September 21, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install vendor patches that close the open‑redirect flaw in /login.html.
  • Implement input validation for the Host header used by /login.html, ensuring only trusted hostnames are allowed and rejecting any other values.
  • If the redirect functionality is not required, disable the redirect feature or block access to /login.html from external sources.

Generated by OpenCVE AI on September 21, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title ST Engineering iDirect Evolution/Velocity WebServer Evolution Management Service login.html redirect
First Time appeared St Engineering Idirect
St Engineering Idirect evolution
St Engineering Idirect velocity Webserver Evolution
Weaknesses CWE-601
CPEs cpe:2.3:a:st_engineering_idirect:evolution:*:*:*:*:*:*:*:*
cpe:2.3:a:st_engineering_idirect:velocity_webserver_evolution:*:*:*:*:*:*:*:*
Vendors & Products St Engineering Idirect
St Engineering Idirect evolution
St Engineering Idirect velocity Webserver Evolution
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

St Engineering Idirect Evolution Velocity Webserver Evolution
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T12:15:08.559Z

Reserved: 2026-09-21T05:52:16.238Z

Link: CVE-2026-94214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-21T13:17:12.170

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-94214

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T13:30:16Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')