THREAT OPS › Threat News › [NVD] CVE-2026-38057 (HIGH 8.1) — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, w
[NVD] CVE-2026-38057 (HIGH 8.1) — The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, w
CVE-2026-38057 CVSS: 8.1 HIGH Published: 2026-07-10T15:16:39.397
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automat
Indicators of compromise
- CVE-2026-38057cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-38057