Record summary

CVE-2025-71318 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 8, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListVersion range not suppliedaffected

Proofs of concept

1

Catalogued exploits

ExploitDBNetman 204 - Remote command without authenticationExploitDB exploitby Parsa Rezaie KhiabanlooNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

4