gerico-lab/riello-multiple-vulnerabilities-2025

gerico-lab/riello-multiple-vulnerabilities-2025

Releases0
Riello UPS Multiple Vulnerabilities - 2025

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

5.5 MEDIUM

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.

9.1 CRITICAL

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.