๐Ÿ” CVE Alert

CVE-2025-71318

CRITICAL 9.8

NetMan 204 Missing Authentication for Administrative Functions

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands โ€” including shutdown, reboot, switch-on-bypass, and battery test โ€” without supplying any credentials.

CWE CWE-306
Vendor riello ups
Product netman 204
Published Jun 5, 2026
Last Updated Jun 8, 2026
Stay Ahead of the Next One

Get instant alerts for riello ups netman 204

Be the first to know when new critical vulnerabilities affecting riello ups netman 204 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Riello UPS / NetMan 204
0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/52183 riello-ups.com: https://www.riello-ups.com/downloads/25-netman-204 vulncheck.com: https://www.vulncheck.com/advisories/netman-204-missing-authentication-for-administrative-functions

Credits

parsa rezaie khiabanloo