PT-2026-49827 · Radiflow · Isap Smart Collector

Published

2026-06-16

·

Updated

2026-06-16

·

CVE-2026-22313

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operating system.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-22313

Affected Products

Isap Smart Collector