CVE-2026-22312
HIGHRadiflow iSAP Smart Collector 3.07-1 - Hard-coded API Token Command Execution
Title source: manualDescription
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).
References (1)
Core 1
Core References
Third Party Advisory third-party-advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22312
Scores
CVSS v3
8.6
EPSS
0.0023
EPSS Percentile
14.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-798
Status
published
Products (1)
Radiflow/iSAP Smart Collector
3.07-1
Published
Jun 16, 2026
Tracked Since
Jun 17, 2026