NetMan 204 Missing Authentication for Administrative Functions
CVE-2025-71318
Key Information:
- Vendor
Riello Ups
- Status
- Vendor
- CVE Published:
- 5 June 2026
Badges
What is CVE-2025-71318?
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands β including shutdown, reboot, switch-on-bypass, and battery test β without supplying any credentials.
Affected Version(s)
NetMan 204 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
