NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.

Project Subscriptions

Vendors Products
Riello-ups Subscribe
Netman 204 Subscribe
Netman 204 Firmware Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 05 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
Description NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.
Title NetMan 204 Missing Authentication for Administrative Functions
First Time appeared Riello-ups
Riello-ups netman 204
Riello-ups netman 204 Firmware
Weaknesses CWE-306
CPEs cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:*
cpe:2.3:o:riello-ups:netman_204_firmware:-:*:*:*:*:*:*:*
Vendors & Products Riello-ups
Riello-ups netman 204
Riello-ups netman 204 Firmware
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-05T17:49:51.355Z

Reserved: 2026-06-05T16:56:46.183Z

Link: CVE-2025-71318

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-05T18:16:54.910

Modified: 2026-06-05T19:02:13.790

Link: CVE-2025-71318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T20:00:04Z

Weaknesses