NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.

Project Subscriptions

Vendors Products
Riello-ups Subscribe
Netman 204 Subscribe
Netman 204 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 08 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.
Title NetMan 204 Missing Authentication for Administrative Functions
First Time appeared Riello-ups
Riello-ups netman 204
Riello-ups netman 204 Firmware
Weaknesses CWE-306
CPEs cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*
cpe:2.3:o:riello-ups:netman_204_firmware:-:*:*:*:*:*:*:*
Vendors & Products Riello-ups
Riello-ups netman 204
Riello-ups netman 204 Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-08T16:14:03.898Z

Reserved: 2026-06-05T16:56:46.183Z

Link: CVE-2025-71318

cve-icon Vulnrichment

Updated: 2026-06-08T16:13:56.608Z

cve-icon NVD

Status : Deferred

Published: 2026-06-05T18:16:54.910

Modified: 2026-06-05T19:02:13.790

Link: CVE-2025-71318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T20:00:04Z

Weaknesses