← Vulnerability feed

Vulnerability record · CVE-2024-8877 · published 25 September 2024

CVE-2024-8877: Riello Netman 204 SQL injection in measurement data database

Riello Ups · Netman 204 Firmware

Riello Netman 204 firmware through 4.05 fails to neutralize special elements, allowing SQL injection into the SQLite database that stores measurement data. The flaw is remotely reachable without authentication, so an exposed device can be queried or manipulated by anyone who can reach its interface.

6.9 CVSS 4.0 Medium EPSS 77% · top 0.5% CWE-89 · SQL injection
6.9CVSS 4.0 base score
77%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityThe flaw is remotely exploitable without authentication but is limited to a measurement database with low confidentiality and integrity impact and no known in-the-wild exploitation.

What it is

Riello Netman 204 firmware through 4.05 fails to neutralize special elements, allowing SQL injection into the SQLite database that stores measurement data. The flaw is remotely reachable without authentication, so an exposed device can be queried or manipulated by anyone who can reach its interface.

Impact

An attacker can read and modify the measurement data stored in the device's SQLite database, which may allow falsified readings or limited data tampering. The CVSS vector rates confidentiality and integrity impact as low and availability impact as none.

Attack surface

The CVSS 4.0 vector is network-based with no privileges and no user interaction required, so the injection is reachable directly over the network. The description does not state which endpoint or parameter is vulnerable, so the exact entry point is unknown.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.77265 (99.5th percentile), but the references are only a vendor advisory and a Full Disclosure post, with no public exploit code or in-the-wild reporting confirmed.

What to do

  • Upgrade Netman 204 firmware beyond 4.05 to a version that fixes the SQL injection.
  • If patching is not possible, restrict network access to the device to trusted management hosts only.
  • Place the device behind a firewall or VPN and avoid exposing its web interface to the internet.
  • Review the vendor advisory and Full Disclosure post for any additional workarounds or indicators.
  • Monitor the SQLite measurement database for unexpected changes or corruption.

Detection

  • Inspect HTTP requests to the Netman 204 interface for SQL metacharacters such as quotes, UNION, or comment sequences.
  • Alert on unexpected changes to the measurement data database or anomalous query patterns.
  • Baseline normal device traffic and flag new or unusual source IPs reaching the management interface.
  • Check device logs for repeated failed or malformed requests that could indicate injection probing.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-8877 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-8878Riello-ups netman 204 firmware weak password recovery vulnerabilityThe password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control …EPSS 1.3%9.8CVE-2022-47893Riello-ups netman 204 firmware unrestricted file upload vulnerabilityThere is a remote code execution vulnerability that affects all versions of NetMan 204. A remote attacker could upload a firmware file containing a w…EPSS 1.2%9.8CVE-2017-6900Riello-ups netman 204 firmware vulnerabilityAn issue was discovered in Riello NetMan 204 14-2 and 15-2. The issue is with the login script and wrongpass Python script used for authentication. W…EPSS 2.6%8.8CVE-2022-47891Riello-ups netman 204 firmware hard-coded credentials vulnerabilityAll versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device to reset the administrator password via the legitimat…EPSS 0.61%8.8CVE-2022-3372Riello-ups netman 204 firmware cross-site request forgery vulnerabilityThere is a CSRF vulnerability on Netman-204 version 02.05. An attacker could manage to change administrator passwords through a Cross Site Request Fo…EPSS 0.35%7.5CVE-2022-47892Riello-ups netman 204 firmware information exposure vulnerabilityAll versions of NetMan 204 could allow an unauthenticated remote attacker to read a file (config.cgi) containing sensitive information, like credenti…EPSS 0.48%9.8CVE-2026-76461Cisco AsyncOS email parsing SQL injection allows root command executionCisco AsyncOS Software for Cisco Secure Email Gateway fails to properly validate email parsing input, allowing crafted email messages containing mali…KEVEPSS 28%analysed9.3CVE-2026-9586Sangoma Switchvox unauthenticated SQL injection in /pa endpointSangoma Switchvox SMB Edition 8.3 (104997) fails to sanitize the PhoneIP value from XML content beginning with <PolycomIPPhone> before concatenating …KEVEPSS 19%analysed

Source: NIST National Vulnerability Database (record CVE-2024-8877), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.