CVE-2025-68916
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 2.56%
- CWE
- CWE-25
- Published
- 2025-12-24
- Last modified
- 2026-03-13
Affected products
- Riello NetMan
Weakness type
Related vulnerabilities
- CVE-2026-68959 — SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this...
- CVE-2026-23877 — Directory Traversal & Filesystem can be accessed by a non-admin user
- CVE-2025-58286 — Denial of service (DoS) vulnerability in the office service. Successful exploitation of this...
- CVE-2025-0225 — Tsinghua Unigroup Electronic Archives System exampleDownload.html path traversal
- CVE-2023-6947 — Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
- CVE-2024-2442 — Path Traversal vulnerability in Franklin Fueling System EVO 550/5000
- CVE-2023-52138 — Path traversal via crafted cpio archives in Engrampa archivers
- CVE-2023-6919 — Path Traversal in VGuard IP Camera Network Recorder