PT-2026-47013 · Enetman · Enetman

CVE-2025-71317

·

Published

2026-06-05

·

Updated

2026-06-12

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetMan version 204
Description NetMan contains a hard-coded backdoor account with the username and password eurek that provides administrative access. A remote, unauthenticated attacker can authenticate through the "/cgi-bin/login.cgi" endpoint using the username and password parameters to obtain administrator privileges. Due to lax parameter validation, the authentication request can be simplified. Once authenticated, an attacker can modify device configurations, enable telnet or SSH services, and reset local user credentials.
Recommendations Update NetMan version 204 to a newer version that removes the hard-coded backdoor account.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71317

Affected Products

Enetman