The device has two web servers that expose unauthenticated REST APIs on the management network (TCP
ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary
commands that are executed with administrative permissions by the underlying operating system.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.cvcn.gov.it/cvcn/cve/CVE-2025-3499 |
|
History
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 09 Jul 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with administrative permissions by the underlying operating system. | |
| Title | Unauthenticated execution of arbitrary commands in Radiflow iSAP Smart Collector | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ENISA
Published: 2025-07-09T08:57:26.893Z
Updated: 2025-07-09T13:08:05.257Z
Reserved: 2025-04-10T08:40:15.892Z
Link: CVE-2025-3499
Updated: 2025-07-09T13:07:54.556Z
Status : Awaiting Analysis
Published: 2025-07-09T09:15:27.297
Modified: 2025-07-10T13:17:30.017
Link: CVE-2025-3499
No data.
ReportizFlow