CVE-2024-8878
The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 1.26%
- CWE
- CWE-640
- Published
- 2024-09-24
- Last modified
- 2026-03-13
Affected products
- Riello Netman 204
Weakness type
Related vulnerabilities
- CVE-2023-7028 — Weak Password Recovery Mechanism for Forgotten Password in GitLab
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2023-30466 — Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
- CVE-2022-3485 — Weak Password Recovery in ifm moneo appliance
- CVE-2024-11350 — AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
- CVE-2022-50910 — Beehive Forum - Account Takeover