CVE-2026-22312
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.6 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Vulnerability Description
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).
and execute some commands (e.g. system reboot).
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-798
Source
NVD
Vendor
Radiflow
Product
iSAP Smart Collector
Discussion (0)
Add Comment
No comments yet. Be the first!