Back to Database
Status published
Medium
CVE-2025-68914
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username...
Vulnerability Description
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68914
Credits & Attribution
No credits recorded in the NVD database.
More from Riello
View All →CVE-2025-68916
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../...
Critical
9.1
CVE-2025-68915
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS...
Medium
5.5
CVE-2024-8878
Unauthenticated Password Reset
Critical
10
CVE-2024-8877
SQL Injection
Medium
6.9
Affected Vendor
Riello
View all reports →Affected Software
NetMan
Vulnerable Versions:
208
Timeline
Official Publish:
December 24th, 2025
Last Modified:
December 24th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N