netman_208 vulnerabilities
CVEs whose affected-version data names the netman_208 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-68916Critical· 9.1Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
▾ Midnightriello-ups · netman_208EPSS 2.6%via NVD
CVE-2025-68915Medium· 5.5Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
▾ Sunlitriello-ups · netman_208EPSS 0.20%via NVD
CVE-2025-68914Medium· 6.5Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.
▾ Sunlitriello-ups · netman_208EPSS 0.22%via NVD