CVE-2025-68914 describes a SQL injection vulnerability in Riello UPS NetMan 208 Application versions prior to 1.12, specifically within the cgi-bin/login.cgi username parameter. This medium-severity vulnerability (CVSS 5.3) allows an unauthenticated attacker to remotely impact data integrity, such as deleting the LOGINFAILEDTABLE. While no public exploit code, Metasploit modules, or Nuclei templates are currently available, and there is no evidence of active exploitation or significant community discussion, organizations using affected versions should prioritize patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12CPE matchmatch criteria | cpe:2.3:a:riello-ups:netman_208:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.