NetMan 204 fails to enforce authentication on its...
Critical severity
Unreviewed
Published
Jun 5, 2026
to the GitHub Advisory Database
•
Updated Jun 5, 2026
Description
Published by the National Vulnerability Database
Jun 5, 2026
Published to the GitHub Advisory Database
Jun 5, 2026
Last updated
Jun 5, 2026
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, administration-commands.html, and configuration.html) to disclose sensitive information including LDAP configuration and active user details, and can invoke privileged UPS control commands — including shutdown, reboot, switch-on-bypass, and battery test — without supplying any credentials.
References