GPU VulnDB

Database/Firmware, BMC & network fabric

Riello NetMan 208: unauthenticated SQL injection in the login form allows database tampering

CVSS 5.3CVE-2025-68914Firmware, BMC & network fabriccurated

Impact

The username parameter of the login CGI is injectable before authentication. The record's own example is deleting the LOGINFAILEDTABLE table, so an unauthenticated attacker can modify the card's local database - including the record of failed logins that would otherwise show brute-force activity against the UPS management interface. Scored for limited integrity impact only; the record does not claim data disclosure or code execution from this issue. The practical concern for an operator is a pre-auth write primitive on a facility-power device that sits on the management network.

Who can reach it

Anyone who can reach the card's HTTP login page - typically anyone on the management VLAN. No authentication required.

What to do

Update the NetMan 208 application to 1.12 or later - a card firmware/application update that reboots the management card without interrupting UPS output. Pending that, block the card's web interface from general management-network reachability and treat its login/audit records as untrustworthy for the exposed period.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.