Executive brief
Radiflow iSAP Smart Collector, a device used for industrial network monitoring and data collection, contains a security flaw in its management interface. An attacker can bypass security controls to view sensitive system settings, change the device configuration, or force the system to reboot. This could lead to unauthorized access to industrial network data or a disruption of monitoring services.
Technical details
The Radiflow iSAP Smart Collector (version 3.07-1) exposes a REST API on TCP port 8086 that relies on a constant, hard-coded authentication token (CWE-798). Because the token is static and universal, an unauthenticated attacker with network access to the management interface can interact with the API as an administrator. This allows for the retrieval of system settings, modification of device configurations, and the execution of administrative commands such as system reboots. The vulnerability is exploitable over the network without user interaction.
Affected products
- Radiflow iSAP Smart Collector 3.07-1
Timeline
- 2026-06-16: disclosed: Initial publication of the CVE record