CVE-2026-22313

CRITICAL

OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector

Title source: cna
STIX 2.1

Description

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22313

Scores

CVSS v3 9.1
EPSS 0.0092
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Radiflow/iSAP Smart Collector 3.07-1
Published Jun 16, 2026
Tracked Since Jun 17, 2026