CVE-2025-3498

9.9

Radiflow · iSAP Smart Collector

The Radiflow iSAP Smart Collector lacks authentication for critical management functions, allowing unauthenticated users to modify device configurations.

Executive summary

A critical authentication bypass vulnerability in the Radiflow iSAP Smart Collector enables unauthenticated users to modify system configurations, leading to unauthorized control.

Vulnerability

The device fails to enforce authentication for critical management functions (CWE-306). This allows an unauthenticated user with network access to the management interface to retrieve and modify the device's configuration settings.

Business impact

The ability to modify configuration settings without authentication carries a CVSS score of 9.9, indicating critical severity. Successful exploitation could allow an attacker to alter the device's behavior, potentially resulting in unauthorized data access, system instability, or the subversion of security controls within the industrial network.

Remediation

Immediate Action: Update the Radiflow iSAP Smart Collector to version 3.02-1 or later to resolve the missing authentication flaw.

Proactive Monitoring: Review system configuration change logs for unauthorized modifications that occur outside of approved maintenance windows.

Compensating Controls: Isolate the management network from the broader corporate network and restrict access to the device's web management interface via strict Access Control Lists (ACLs).

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the ease of access and the potential for configuration tampering, this vulnerability poses a significant risk to operational integrity. Administrators are urged to update to the latest version immediately and ensure that management interfaces are protected by network-level access controls.