The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration
and execute some commands (e.g. system reboot).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22312 |
|
History
Tue, 16 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot). | |
| Title | Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart Collector | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-06-16T18:38:16.344Z
Reserved: 2026-01-07T09:31:00.563Z
Link: CVE-2026-22312
No data.
Status : Received
Published: 2026-06-16T20:16:28.590
Modified: 2026-06-16T20:16:28.590
Link: CVE-2026-22312
No data.
OpenCVE Enrichment
No data.