Open Redirect Vulnerability in ST Engineering iDirect Evolution and Velocity WebServer
CVE-2026-94214
Key Information:
- Vendor
St Engineering Idirect
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94214?
A security flaw has been identified in ST Engineering iDirect Evolution and Velocity WebServer affecting the Management Service's login component. The vulnerability arises from improper handling of the Host header in the /login.html file, enabling attackers to manipulate URL requests resulting in open redirects. This manipulation permits remote exploitation, potentially allowing attackers to redirect users to malicious sites. The vulnerability has been publicly disclosed, and timely action is necessary to mitigate the risk, especially as the vendor has not yet responded to the alert regarding this significant issue.
Affected Version(s)
Evolution 20260717
Velocity WebServer Evolution 20260717
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
