9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials.
AI Analysis
Hard-coded backdoor account in NetMan 204 allowing remote, unauthenticated administrative access
Basic Information
ID
CVE-2025-71317
Source
VulnCheck
Published
Jun 5, 2026 at 17:49
Affected Product
Vendor
Riello UPS
Product
NetMan 204
Affected Versions
Riello UPS NetMan 204 0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Riello UPS
Product
NetMan 204