CVE-2025-68916CWE-25

Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution

Critical · published December 24, 2025

CVSS v3.1
9.1
EPSS
3%
Percentile
84.0
In the wild
Unconfirmed
What it is

🚨 A sneaky directory traversal vulnerability in Riello UPS NetMan 208 could allow attackers to upload files and execute code - all through a simple misstep! 🔥 Think of it like a delivery person being handed the wrong address—if they follow the instructions without double-checking, they might drop off a package at a very sensitive location! An attacker could exploit this flaw to upload malicious files and execute arbitrary code on the UPS management system, leading to total control over the device. This means they could disrupt operations, steal sensitive data, or even cause physical damage to connected equipment. The consequences could be absolutely devastating!

Put simply

Think of it like a delivery person being handed the wrong address—if they follow the instructions without double-checking, they might drop off a package at a very sensitive location! This vulnerability allows a malicious actor to manipulate the input to the 'certsupload.cgi' endpoint, successfully traversing directories to upload harmful files. Essentially, this opens a backdoor for executing any code they choose, compromising the entire system.

What to do

An attacker could exploit this flaw to upload malicious files and execute arbitrary code on the UPS management system, leading to total control over the device. This means they could disrupt operations, steal sensitive data, or even cause physical damage to connected equipment. The consequences could be absolutely devastating! Immediate action is required: update the application to version 1.12 or later to close this vulnerability. Additionally, review your file upload configurations to ensure strict input validation and directory access controls are enforced. You've got this! By taking these steps, you'll secure your system and keep the bad guys at bay. 🛡️

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.02560 · 84.0th percentile
Weakness
CWE-25 · Path Traversal: '/../filedir'
Published
2025-12-24T19:43Z
EPSS history
Timeline
  • 24 DEC 19:43Z
    Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution
    cvelistv5