Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 05 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials. | |
| Title | NetMan 204 Hard-coded Backdoor Credentials | |
| First Time appeared |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:* cpe:2.3:o:riello-ups:netman_204_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-05T19:35:30.991Z
Reserved: 2026-06-05T16:56:46.183Z
Link: CVE-2025-71317
Updated: 2026-06-05T19:35:26.967Z
Status : Deferred
Published: 2026-06-05T18:16:54.737
Modified: 2026-06-05T19:02:13.790
Link: CVE-2025-71317
No data.
OpenCVE Enrichment
Updated: 2026-06-05T20:00:04Z