CVE-2025-3498: Unauthenticated modification of Radiflow iSAP Smart Collector configuration
An unauthenticated user with management network access can get and modify the Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) configuration. The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). An attacker can use these APIs to get access to all system settings, modify the configuration and execute some commands (e.g., system reboot).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3498?
CVE-2025-3498 has been classified with a high severity due to the potential for unauthorized access and modification of system configurations.
How do I fix CVE-2025-3498?
To mitigate CVE-2025-3498, restrict access to the management network and implement authentication for the exposed REST APIs.
What are the affected products of CVE-2025-3498?
CVE-2025-3498 affects the Radiflow iSAP Smart Collector running on CentOS 7, specifically version VSAP 1.20.
Can an attacker exploit CVE-2025-3498 remotely?
Yes, an attacker on the same management network can exploit CVE-2025-3498 remotely because of the unauthenticated access to the web servers.
What actions can an attacker perform through CVE-2025-3498?
An attacker exploiting CVE-2025-3498 can obtain and modify the configuration of the Radiflow iSAP Smart Collector, compromising the device's security.