Back to CVE List

CVE-2026-22312

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.6 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Vulnerability Description

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-798
Source
NVD
Vendor
Radiflow
Product
iSAP Smart Collector

External References

Discussion (0)

Add Comment

No comments yet. Be the first!