The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system.
History

Tue, 15 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00321}

epss

{'score': 0.00453}


Wed, 09 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Jul 2025 09:15:00 +0000

Type Values Removed Values Added
Description The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system.
Title Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart Collector
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published: 2025-07-09T08:57:26.893Z

Updated: 2025-07-09T13:08:05.257Z

Reserved: 2025-04-10T08:40:15.892Z

Link: CVE-2025-3499

cve-icon Vulnrichment

Updated: 2025-07-09T13:07:54.556Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-09T09:15:27.297

Modified: 2025-07-10T13:17:30.017

Link: CVE-2025-3499

cve-icon Redhat

No data.