Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 08 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials. | |
| Title | NetMan 204 Missing Authentication for Administrative Functions | |
| First Time appeared |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:* cpe:2.3:o:riello-ups:netman_204_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-08T16:14:03.898Z
Reserved: 2026-06-05T16:56:46.183Z
Link: CVE-2025-71318
Updated: 2026-06-08T16:13:56.608Z
Status : Deferred
Published: 2026-06-05T18:16:54.910
Modified: 2026-06-05T19:02:13.790
Link: CVE-2025-71318
No data.
OpenCVE Enrichment
Updated: 2026-06-05T20:00:04Z