PT-2025-28859 · Radiflow · Radiflow Isap Smart Collector

CVE-2025-27027

·

Published

2025-07-09

·

Updated

2025-07-09

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Radiflow iSAP Smart Collector version 1.20
Description: The issue allows a user with vpuser credentials to bypass restricted shell rbash limitations and access a full-featured Linux shell when connecting to the device via SSH. This is possible because the restricted shell only allows a small list of commands, but the vulnerability enables the user to overcome these restrictions.
Recommendations: For Radiflow iSAP Smart Collector version 1.20, consider restricting access to the SSH connection for the vpuser credentials until a patch is available. As a temporary workaround, limit the commands that can be executed within the restricted shell rbash to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-27027

Affected Products

Radiflow Isap Smart Collector