Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
The cgi-bin/certsupload.cgi endpoint does not properly sanitize the uploaded file path, accepting the /../ sequence (path traversal). An attacker can upload an executable file outside the allowed directory — for example, to a location from which the device operating system automatically executes it. As a result, the uploaded payload can be interpreted as code by the CGI server, resulting in remote code execution (RCE) on the device.
An attacker can gain full control over the NetMan 208 device, including reading and modifying its configuration, installing malicious software, and potentially affecting managed UPS backup power supplies. The vulnerability enables breach of confidentiality, integrity, and availability of the system (C:H, I:H, A:H).
The Riello UPS NetMan 208 Application software should be updated to version 1.12 or later. Details are available in the manufacturer's references and in the repository: https://github.com/gerico-lab/riello-multiple-vulnerabilities-2025. Until the patch is applied, it is recommended to limit network access to the device management interface (e.g., through a firewall or dedicated management network).
Riello UPS NetMan 208 Application in versions prior to 1.12.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HRiello Ups Netman 208
APPRiello-Ups< 1.12
Related vulnerabilities
Aplikacja Riello UPS NetMan 208 w wersji przed 1.12 pozwala na SQL injection w parametrze username w cgi-bin/l...
Aplikacja Riello UPS NetMan 208 w wersjach przed 1.12 pozwala na XSS w pliku cgi-bin/loginbanner_w.cgi poprzez...
Podatność mechanizmu odzyskiwania hasła w Riello Netman 204 umożliwia przejęcie urządzenia
RCE w Riello-Ups NetMan 204 — upload webshella przez firmware
Riello NetMan 204 — command injection i bypass uwierzytelnienia