Executive brief
The Radiflow iSAP Smart Collector, a device used for industrial network monitoring and data collection, contains a security flaw in its management interface. An authorized user with access to the management network can take full control of the device by executing unauthorized commands with administrative privileges. This could lead to a complete compromise of the monitoring system, allowing an attacker to disrupt operations or access sensitive industrial data.
Technical details
An OS command injection vulnerability (CWE-78) exists in the REST API of Radiflow iSAP Smart Collector version 3.07-1. The affected webserver, which typically listens on TCP port 8086 of the management network, fails to properly neutralize special elements in API inputs. An attacker with valid authentication tokens can exploit this to execute arbitrary shell commands with root/administrative privileges on the underlying operating system. While the attack requires high privileges (PR:H), the impact is critical as it allows for full control over the device and potential lateral movement within the management environment.
Affected products
- Radiflow iSAP Smart Collector 3.07-1
Timeline
- 2026-06-16: disclosed: Initial disclosure by ENISA/CVCN
- 2026-06-16: advisory: NVD record created