CVE-2026-94214 | ST Engineering iDirect Evolution/Velocity WebServer Evolution up to 20260717 Management Service /login.html Host redirect
A vulnerability marked as problematic has been reported in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the argument Host results in open redirect.
This vulnerability is cataloged as CVE-2026-94214. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More