Direkt release history
Direkt release history
Important information from SRT Alliance Security Advisory
Two critical security vulnerabilities (CVSS 9.1) have been identified and patched in the open-source SRT protocol library. Two CVEs have been published for these vulnerabilities.
It is recommended that you take immediate remediation action by updating to SRT protocol library v1.5.6, which contains fixes for both vulnerabilities. The vulnerabilities affect all versions of the SRT protocol library prior to v1.5.6.
Intinor has upgraded the SRT library accordingly and thus recommends all units to be upgraded to 4.23.4 or 4.24.0_rc9.
Important information regarding Direkt firmware 4.23.2 (and later)
The TLS certificate used by Direkt units will expire on April 5, 2026. This will primarily have an effect on API integrations using the local API of Direkt units.
To ensure continued secure connections, we strongly recommend upgrading your Direkt units to the latest stable firmware 4.23.2 (or later). This firmware version will automatically generate a new self-signed certificate during boot.
Who is Affected?
- API Integrators: Custom integrations relying on local HTTPS will likely require updates to continue functioning. Our new recommendation for API integration is to use “Certificate Pinning” with interactive “Trust on First Use.” Developers can find updated recommendations and examples on GitHub.
- Local Web Interface Users: When accessing the local UI after the update, you will likely encounter a one-time browser security warning due to the new unique certificate.
- FTP Users: The same certificate is used for FTP (port 21). While most standard FTP clients do not strictly validate certificates by default, any clients specifically configured to do so will fail to connect.
Who is NOT Affected?
- Remote Users: Access through ISS (iss.intinor.se) or remote IDM (idm.intinor.se) remains completely unaffected.
If you have any questions or need help updating the firmware, please contact Intinor support.