CVE-2026-22312: Radiflow Isap Smart Collector

High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

Affected products

  • Radiflow Isap Smart Collector: version 3.07-1 only

Published 2026-06-16. Last modified 2026-06-17.