Database/Firmware, BMC & network fabric
Riello NetMan 208: path traversal in certificate upload gives code execution on the UPS management card
Impact
The certificate-upload CGI on the NetMan 208 card accepts /../ in the upload path, so a file can be written outside the intended directory and then executed. That yields code execution on the card that manages a datacenter UPS - the device that reports power state and, in many deployments, is wired into shutdown and load-transfer logic. A foothold there sits on the facility/management network alongside BMCs and PDUs, and it can falsify or suppress power telemetry for a rack of GPU nodes. The record describes the flaw and the fixed version only; it does not state what privileges the implanted code runs with.
Who can reach it
Network access to the card's web interface. The CVSS vector states high privileges are required (AV:N/PR:H), so an authenticated administrative session on the management interface is needed - which in practice means anyone on the management VLAN who holds or can obtain card credentials.
What to do
Update the NetMan 208 application to 1.12 or later; the vendor fix is an application/firmware image pushed to the card, which reboots the management card but does not interrupt the UPS output, so no node drain is required. Until then, keep the card off any routable network, restrict its web interface to a jump host, and rotate card credentials. No workaround is documented in the record.
References
Related entries
- Supermicro BMC firmware validation (MBD-X12STW): RoT bypass, crafted firmware image acceptedCVE-2025-7937 · Supermicro BMC firmware validation (MBD-X12STW)High
- Supermicro BMC web server request handling on MBD-X13SEDW-F: Any account that can log into the BMC web interface canCVE-2025-8076 · Supermicro BMC web server request handling on MBD-X13SEDW-FHigh
- Supermicro BMC web interface (stack buffer overflow, X13SEDW-F): Second authenticated stack overflow in the BMC webCVE-2025-8727 · Supermicro BMC web interface (stack buffer overflow, X13SEDW-F)High
- Arista CloudVision: path traversal lets a high-privilege user read unintended files from the SensorCVE-2026-101153 · Arista CloudVision Portal / CloudVision Sensor (path traversal)High
- Perle IOLAN STS/SCS terminal server (firmware before 6.0): A logged-in user of the restricted admin shell (TelnetCVE-2026-23759 · Perle IOLAN STS/SCS terminal server (firmware before 6.0)High
- Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boards: Crafted characters injectedCVE-2026-3820 · Supermicro BMC SMTP service configuration handler on AS-2115HS-TNR and related boardsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.