There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him to execute arbitrary code as root.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HRiello Ups Netman 204
HWRiello-Upsall versionsRiello Ups Netman 204 Firmware
OSRiello-Upsall versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2024-8878CRITICAL10.0PL ✓same product
Podatność mechanizmu odzyskiwania hasła w Riello Netman 204 umożliwia przejęcie urządzenia
CVE-2017-6900CRITICAL9.8PL ✓same product
Riello NetMan 204 — command injection i bypass uwierzytelnienia
CVE-2022-47891HIGH8.1same product
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the a...
CVE-2022-3372HIGH8.8same product
There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator pa...
CVE-2024-8877MEDIUM6.9same product
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It ...