Executive brief
The NetMan 204 is a network card used to manage and monitor Uninterruptible Power Supply (UPS) systems. A security flaw has been identified where the device contains a built-in 'backdoor' account with a permanent, unchangeable password. An attacker can use these credentials to remotely take full control of the power management system, potentially allowing them to shut down connected servers, change security settings, or disrupt critical power infrastructure.
Technical details
The NetMan 204 firmware contains hard-coded administrative credentials (CWE-798) within the authentication logic. A remote, unauthenticated attacker can gain full administrative access by sending a specially crafted request to the /cgi-bin/login.cgi endpoint using the 'eurek' username and password. Due to lax parameter validation in the login script, the authentication can also be triggered using a shortened URL format (e.g., /cgi-bin/login.cgi?username=eurek%20eurek). Successful exploitation allows for complete device takeover, including the ability to modify system configurations, enable remote management services like SSH or Telnet, and manipulate connected UPS hardware. No patch has been officially confirmed in the advisory, though users are advised to restrict network access to these management interfaces.
Affected products
- Riello UPS NetMan 204 All versions including 2.04
Timeline
- 2025-02-04: other: Vulnerability discovered by researcher
- 2025-04-11: disclosed: Exploit details published on Exploit-DB
- 2026-06-05: advisory: CVE published and NVD record created