CVE-2025-3499

10.0

Radiflow · iSAP Smart Collector

The Radiflow iSAP Smart Collector exposes unauthenticated REST APIs on management ports, allowing remote attackers to execute arbitrary OS commands.

Executive summary

A critical OS command injection vulnerability in the Radiflow iSAP Smart Collector allows unauthenticated attackers to achieve full system compromise via exposed management APIs.

Vulnerability

The device exposes unauthenticated REST APIs on TCP ports 8084 and 8086, which are susceptible to OS command injection (CWE-78). An unauthenticated attacker can leverage these APIs to inject and execute arbitrary commands on the underlying operating system.

Business impact

With a CVSS score of 10.0, this vulnerability represents the highest level of risk. Exploitation grants an attacker full control over the affected device, potentially leading to the compromise of industrial control environments, data theft, and the disruption of critical operations managed by the iSAP Smart Collector.

Remediation

Immediate Action: Update the Radiflow iSAP Smart Collector to version 3.02-1 or later to remediate the API vulnerability.

Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at TCP ports 8084 and 8086.

Compensating Controls: Restrict network access to the management interface by using firewall rules to ensure that only authorized IP addresses can communicate with the device on the specified ports.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

This vulnerability is of critical importance due to its potential for total system takeover. Organizations must verify their current version of the iSAP Smart Collector and apply the available security update immediately to mitigate the risk of remote code execution.