The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22313 |
|
History
Tue, 16 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Radiflow
Radiflow isap Smart Collector |
|
| Vendors & Products |
Radiflow
Radiflow isap Smart Collector |
Tue, 16 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system. | |
| Title | OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-06-16T18:49:30.740Z
Reserved: 2026-01-07T09:31:00.563Z
Link: CVE-2026-22313
No data.
Status : Awaiting Analysis
Published: 2026-06-16T20:16:28.710
Modified: 2026-06-16T20:47:43.440
Link: CVE-2026-22313
No data.
OpenCVE Enrichment
Updated: 2026-06-16T20:45:02Z
Weaknesses