Filtered by vendor Riello-ups Subscriptions
Filtered by product Netman 208 Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-68916 1 Riello-ups 1 Netman 208 2026-01-02 9.1 Critical
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
CVE-2025-68914 1 Riello-ups 1 Netman 208 2026-01-02 6.5 Medium
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.
CVE-2025-68915 1 Riello-ups 1 Netman 208 2026-01-02 5.5 Medium
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.