The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send
arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2026-22313 |
|
History
Tue, 16 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system. | |
| Title | OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published:
Updated: 2026-06-16T18:49:30.740Z
Reserved: 2026-01-07T09:31:00.563Z
Link: CVE-2026-22313
No data.
Status : Received
Published: 2026-06-16T20:16:28.710
Modified: 2026-06-16T20:16:28.710
Link: CVE-2026-22313
No data.
OpenCVE Enrichment
No data.