CVE-2025-71317: NetMan 204 Hard-coded Backdoor Credentials

Published Jun 5, 2026
·
Updated

NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the cgi-bin/login.cgi endpoint (for example /cgi-bin/login.cgi?username=eurek&password=eurek, which due to lax parameter validation can be shortened to /cgi-bin/login.cgi?username=eurek%20eurek) to obtain administrator privileges, allowing them to alter device configuration, enable the telnet/SSH services, and reset local user credentials.

Affected Software

1 affected component
NetMan 204

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove or disable the hard-coded backdoor account with username 'eurek' to prevent its use for administrative authentication.

    NetMan 204 local account 'eurek' = disabled or removed
  2. Configuration

    Disable the CGI login endpoint or restrict access to /cgi-bin/login.cgi to a trusted management network or specific IPs to prevent unauthenticated remote access.

    NetMan 204 (web management) /cgi-bin/login.cgi access = disabled or restricted to trusted hosts
  3. Configuration

    Ensure telnet and SSH services are disabled unless explicitly required; if required, limit access to trusted hosts and enforce strong authentication.

    NetMan 204 telnet and SSH services = disabled unless required
  4. Compensating control

    Block or restrict external access to the device management interfaces (HTTP/CGI, telnet, SSH) at the network edge or firewall; allow management only from trusted IP ranges or via an administrative VPN.

  5. Operational

    Rotate all administrative and local user credentials, audit configuration changes, and review logs for any use of the 'eurek' account or other unauthorized activity; restore secure configurations after removal/mitigation of the backdoor.

Event History

Jun 5, 2026
CVE Published
via MITRE·05:49 PM
Data Sourced
via MITRE·05:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-71317?

CVE-2025-71317 has a critical severity rating of 9.3.

2

How do I fix CVE-2025-71317?

To mitigate CVE-2025-71317, disable the hard-coded backdoor account and implement strong authentication measures.

3

What are the risks associated with CVE-2025-71317?

CVE-2025-71317 allows remote, unauthenticated attackers to gain administrative access, leading to potential data breaches.

4

What is the impact of CVE-2025-71317 on NetMan 204?

CVE-2025-71317 compromises the security of NetMan 204 by providing an easy entry point for attackers.

5

Is there a way to detect exploitation of CVE-2025-71317?

Monitoring for unusual login attempts or changes in system settings can help detect exploitation attempts related to CVE-2025-71317.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203