CRITICAL🇵🇱 Wersja polska

CVE-2025-68916

CVSS 9.1v3.1pub. 2025-12-24upd. 2026-01-02

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

🤖 AI Analysis
How it works

The cgi-bin/certsupload.cgi endpoint does not properly sanitize the uploaded file path, accepting the /../ sequence (path traversal). An attacker can upload an executable file outside the allowed directory — for example, to a location from which the device operating system automatically executes it. As a result, the uploaded payload can be interpreted as code by the CGI server, resulting in remote code execution (RCE) on the device.

Impact

An attacker can gain full control over the NetMan 208 device, including reading and modifying its configuration, installing malicious software, and potentially affecting managed UPS backup power supplies. The vulnerability enables breach of confidentiality, integrity, and availability of the system (C:H, I:H, A:H).

Mitigation & patch

The Riello UPS NetMan 208 Application software should be updated to version 1.12 or later. Details are available in the manufacturer's references and in the repository: https://github.com/gerico-lab/riello-multiple-vulnerabilities-2025. Until the patch is applied, it is recommended to limit network access to the device management interface (e.g., through a firewall or dedicated management network).

Who is affected

Riello UPS NetMan 208 Application in versions prior to 1.12.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Riello Ups Netman 208

    APP
    Riello-Ups
    < 1.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEPath Traversal
CWE
References

Related vulnerabilities

CVE-2025-68914MEDIUM6.5same product

Aplikacja Riello UPS NetMan 208 w wersji przed 1.12 pozwala na SQL injection w parametrze username w cgi-bin/l...

CVE-2025-68915MEDIUM5.5same product

Aplikacja Riello UPS NetMan 208 w wersjach przed 1.12 pozwala na XSS w pliku cgi-bin/loginbanner_w.cgi poprzez...

CVE-2024-8878CRITICAL10.0PL ✓same vendor

Podatność mechanizmu odzyskiwania hasła w Riello Netman 204 umożliwia przejęcie urządzenia

CVE-2022-47893CRITICAL10.0PL ✓same vendor

RCE w Riello-Ups NetMan 204 — upload webshella przez firmware

CVE-2017-6900CRITICAL9.8PL ✓same vendor

Riello NetMan 204 — command injection i bypass uwierzytelnienia