Junglewise Threat Intelligence

CVE-2025-71318: Riello UPS NetMan 204 missing authentication in administrative interface

CVE-2025-71318 · Severity: critical · CVSS 9.8 · Published 2026-06-05

Executive brief

The NetMan 204 network agent, used to manage Uninterruptible Power Supply (UPS) systems, fails to require a password for its administrative interface. This allows an unauthorized person to remotely access sensitive configuration data or issue commands to shut down, reboot, or bypass the power supply. Such an attack could lead to immediate power loss for connected servers and critical infrastructure, causing significant operational downtime.

Technical details

The NetMan 204 firmware contains a missing authentication vulnerability (CWE-306) affecting its web-based management interface. Remote, unauthenticated attackers can bypass the login screen by directly requesting administrative HTML pages and CGI endpoints. This exposure allows for the disclosure of LDAP configurations, firmware details, and active user sessions. Furthermore, attackers can invoke critical UPS functions via command endpoints, including 'shutdown', 'reboot', 'switch-on-bypass', and 'battery-test', without providing credentials. The vulnerability is easily exploitable via direct HTTP requests to paths such as /administration-commands.html and /configuration.html.

Affected products

  • Riello UPS NetMan 204 All versions up to and including 2025 releases

Timeline

  • 2025-02-04: other: Vulnerability discovered by researcher
  • 2025-04-11: disclosed: Exploit details published on Exploit-DB
  • 2026-06-05: advisory: CVE published and NVD record created

References

Related threats