CVE-2025-3499: Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart Collector
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3499?
CVE-2025-3499 is rated as a critical vulnerability due to its potential for remote exploitation with administrative permissions.
How do I fix CVE-2025-3499?
To mitigate CVE-2025-3499, ensure that access to the affected REST APIs is restricted and apply any available security patches from Radiflow.
What are the impacted systems for CVE-2025-3499?
CVE-2025-3499 specifically affects the Radiflow iSAP Smart Collector device.
Can CVE-2025-3499 be exploited remotely?
Yes, CVE-2025-3499 can be exploited remotely through unauthenticated access to the device's REST APIs.
What kind of threats does CVE-2025-3499 pose?
CVE-2025-3499 poses a threat of OS command injection, allowing attackers to execute arbitrary commands on affected devices with high privileges.