Radiflow Vulnerabilities and Affected Products
Vulnerabilities associated with iSAP Smart Collector.
Products
Clear product- iSAP Smart Collector7 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-22313CRITICAL | OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart CollectorThe device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system. CWE-78Jun 16, 2026 | CVSS9.1v3.1 | EPSS0.921% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-22312HIGH | Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart CollectorThe device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot). CWE-798Jun 16, 2026 | CVSS8.6v3.1 | EPSS0.232% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3499CRITICAL | Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart CollectorThe device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system. CWE-78Jul 9, 2025 | CVSS10.0v3.1 | EPSS1.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3498CRITICAL | Unauthenticated modification of Radiflow iSAP Smart Collector configurationAn unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration and execute some commands (e.g., system reboot). CWE-306Jul 9, 2025 | CVSS9.9v3.1 | EPSS0.281% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-3497HIGH | Radiflow iSAP Smart Collector Linux distribution unmaintainedThe Linux distribution underlying the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) is obsolete and reached end of life (EOL) on June 30, 2024. Thus, any unmitigated vulnerability could be exploited to affect this product. CWE-1104Jul 9, 2025 | CVSS8.7v3.1 | EPSS0.334% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27028MEDIUM | Read access of deprivileged Radiflow iSAP Smart Collector userThe Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash). CWE-266Jul 9, 2025 | CVSS6.8v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-27027MEDIUM | Restricted shell evasion in Radiflow iSAP Smart CollectorA user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing the rbash restrictions. CWE-653Jul 9, 2025 | CVSS4.1v3.1 | EPSS0.246% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |