CVE-2024-8878 CRITICAL

CVE-2024-8878: Unauthenticated Password Reset

Vendor Riello
Product Netman 204
Weakness CWE-640 · Weak password recovery
Published September 24, 2024
Last update November 4, 2025

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

The password recovery mechanism for the forgotten password in Riello Netman 204 allows an attacker to reset the admin password and take over control of the device.This issue affects Netman 204: through 4.05.

Key dates

02Disclosure timeline

September 24, 2024 CVE published
November 4, 2025 Record updated