Riello Ups develops a narrow line of network management cards and firmware for uninterruptible power supplies, components that occupy a specialized niche in critical infrastructure and data-center environments. The vendor's vulnerability disclosures center on its NetMan 204 and NetMan 208 management interfaces, which serve as out-of-band access points to power-distribution and failover systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Riello Ups over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8877CRITICAL Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue | Sep 25, 2024 | 9.8 | 76 | NO | YES |
CVE-2017-6900CRITICAL An issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. When calling wrongpass, the vari | Jul 3, 2019 | 9.8 | 31 | NO | NO |
CVE-2022-47893CRITICAL There is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a webshell, that could allow him t | Oct 3, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-68916HIGH Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution. | Dec 24, 2025 | 7.2 | 27 | NO | NO |
CVE-2024-8878CRITICAL The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affect | Sep 25, 2024 | 9.8 | 26 | NO | NO |
CVE-2022-47891HIGH All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimate recovery function. | Oct 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2022-47892HIGH All versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credentials. | Oct 3, 2023 | 7.5 | 22 | NO | NO |
CVE-2022-3372HIGH There is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Forgery due to the lack of proper | Jun 21, 2023 | 8.8 | 21 | NO | NO |
CVE-2025-68914MEDIUM Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table. | Dec 24, 2025 | 5.3 | 20 | NO | NO |
CVE-2025-68915MEDIUM Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner. | Dec 24, 2025 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Riello Ups.
Media articles that mention a CVE ID that affects a product developed by Riello Ups — matched by CVE ID, not by vendor name.