CVE-2025-68914: Riello-Ups Netman 208

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker can delete the LOGINFAILEDTABLE table.

Affected products

  • Riello-Ups Netman 208: before 1.12 (fixed in 1.12)

Published 2025-12-24. Last modified 2026-10-07.