THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-38057 (HIGH 8.1) — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, w

[NVD] CVE-2026-38057 (HIGH 8.1) — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, w

lownvdPublished 2026-07-10

CVE-2026-38057 CVSS: 8.1 HIGH Published: 2026-07-10T15:16:39.397

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automat

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-38057