Impact
An authenticated attacker can exploit the device's webserver, which hosts a REST API secured by a token, to inject arbitrary OS commands. These commands are executed with administrative privileges, enabling the attacker to modify device configuration, exfiltrate data, or launch further attacks. The flaw is OS command injection, commonly categorized under CWE-78.
Affected Systems
Radiflow iSAP Smart Collector devices. No specific version details are listed in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1, indicating critical severity. EPSS indicates a very low probability (<1%) that exploitation will occur, and the issue is not included in the CISA KEV catalog. The likely attack vector is through authenticated access to the webserver's REST API on the management network, which is often reachable only from trusted internal hosts. Without a patch, an attacker who can obtain a valid token could execute any command with system‑level privileges, leading to full compromise of the device.
OpenCVE Enrichment