CVE-2025-3498
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
09/07/2025
Last modified:
10/07/2025
Description
An unauthenticated user with management network access can get and <br />
modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) <br />
configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP<br />
ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration<br />
and execute some commands (e.g., system reboot).
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL