CVE-2026-22313
CRITICALOS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector
Title source: cnaDescription
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
References (1)
Core 1
Core References
Third Party Advisory third-party-advisory
https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22313
Scores
CVSS v3
9.1
EPSS
0.0092
EPSS Percentile
56.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
Radiflow/iSAP Smart Collector
3.07-1
Published
Jun 16, 2026
Tracked Since
Jun 17, 2026