CVE-2025-71318
CRITICAL
NetMan 204 Missing Authentication for Administrative Functions
Record summary
CVE-2025-71318 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 8, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
NetMan 204Browse Riello UPS / NetMan 204 | CVE List | Version range not supplied | affected |
Proofs of concept
1Catalogued exploits
ExploitDBNetman 204 - Remote command without authenticationExploitDB exploitby Parsa Rezaie KhiabanlooNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-71318 Exploit-DBexploit
https://www.exploit-db.com/exploits/52183 Vendorproduct
https://www.riello-ups.com/downloads/25-netman-204 VulnCheck Advisory: NetMan 204 Missing Authentication for Administrative FunctionsThird-party advisory
https://www.vulncheck.com/advisories/netman-204-missing-authentication-for-administrative-functions