CVE-2025-3498

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
09/07/2025
Last modified:
10/07/2025

Description

An unauthenticated user with management network access can get and <br /> modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) <br /> configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP<br /> ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration<br /> and execute some commands (e.g., system reboot).

References to Advisories, Solutions, and Tools