CVE-2025-27028: Radiflow Isap Smart Collector

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging to other users and having restricted access (like, for example, the root password hash).

Affected products

  • Radiflow Isap Smart Collector: from 1.20, before 3.02-1 (fixed in 3.02-1)

Published 2025-07-09. Last modified 2026-06-17.