NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 05 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials. | |
| Title | NetMan 204 Hard-coded Backdoor Credentials | |
| First Time appeared |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| Weaknesses | CWE-798 | |
| CPEs | cpe:2.3:h:riello-ups:netman_204:-:*:*:*:*:*:*:* cpe:2.3:o:riello-ups:netman_204_firmware:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Riello-ups
Riello-ups netman 204 Riello-ups netman 204 Firmware |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-05T17:49:50.474Z
Reserved: 2026-06-05T16:56:46.183Z
Link: CVE-2025-71317
No data.
Status : Deferred
Published: 2026-06-05T18:16:54.737
Modified: 2026-06-05T19:02:13.790
Link: CVE-2025-71317
No data.
OpenCVE Enrichment
Updated: 2026-06-05T19:30:02Z
Weaknesses