Vulnerability record · CVE-2024-8877 · published 25 September 2024
CVE-2024-8877: Riello Netman 204 SQL injection in measurement data database
Riello Ups · Netman 204 Firmware
Riello Netman 204 firmware through 4.05 fails to neutralize special elements, allowing SQL injection into the SQLite database that stores measurement data. The flaw is remotely reachable without authentication, so an exposed device can be queried or manipulated by anyone who can reach its interface.
Description
Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
medium priorityThe flaw is remotely exploitable without authentication but is limited to a measurement database with low confidentiality and integrity impact and no known in-the-wild exploitation.
What it is
Riello Netman 204 firmware through 4.05 fails to neutralize special elements, allowing SQL injection into the SQLite database that stores measurement data. The flaw is remotely reachable without authentication, so an exposed device can be queried or manipulated by anyone who can reach its interface.
Impact
An attacker can read and modify the measurement data stored in the device's SQLite database, which may allow falsified readings or limited data tampering. The CVSS vector rates confidentiality and integrity impact as low and availability impact as none.
Attack surface
The CVSS 4.0 vector is network-based with no privileges and no user interaction required, so the injection is reachable directly over the network. The description does not state which endpoint or parameter is vulnerable, so the exact entry point is unknown.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high at 0.77265 (99.5th percentile), but the references are only a vendor advisory and a Full Disclosure post, with no public exploit code or in-the-wild reporting confirmed.
What to do
- Upgrade Netman 204 firmware beyond 4.05 to a version that fixes the SQL injection.
- If patching is not possible, restrict network access to the device to trusted management hosts only.
- Place the device behind a firewall or VPN and avoid exposing its web interface to the internet.
- Review the vendor advisory and Full Disclosure post for any additional workarounds or indicators.
- Monitor the SQLite measurement database for unexpected changes or corruption.
Detection
- Inspect HTTP requests to the Netman 204 interface for SQL metacharacters such as quotes, UNION, or comment sequences.
- Alert on unexpected changes to the measurement data database or anomalous query patterns.
- Baseline normal device traffic and flag new or unusual source IPs reaching the management interface.
- Check device logs for repeated failed or malformed requests that could indicate injection probing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-8877 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-8877), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.