CVE-2026-22312

HIGH

Radiflow iSAP Smart Collector 3.07-1 - Hard-coded API Token Command Execution

Title source: manual
STIX 2.1

Description

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22312

Scores

CVSS v3 8.6
EPSS 0.0023
EPSS Percentile 14.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
Radiflow/iSAP Smart Collector 3.07-1
Published Jun 16, 2026
Tracked Since Jun 17, 2026