CVE-2026-44402
nicheUnauthenticated RCE in Voltronic Power SNMP Web Pro 1.1
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution flaw (CWE-434) in the upload.cgi firmware update endpoint, which accepts a tar archive without requiring valid credentials. A remote attacker sends a crafted tar archive whose contents are extracted into a privileged directory and executed, giving the attacker arbitrary command execution as root on the device. Successful exploitation results in full compromise of the web management unit, which attackers can then use as a foothold into the surrounding network. Affected users are organizations running SNMP Web Pro 1.1 firmware on Voltronic Power UPS management hardware. Exploitation has not been confirmed in the wild: the flaw is not in CISA KEV, EPSS puts 30-day exploitation probability at 0.9%, but a public proof-of-concept is available on GitHub, so opportunistic scanning is plausible.
What to do: Contact Voltronic Power or your UPS reseller for patched SNMP Web Pro firmware beyond 1.1, as no fixed version is specified in the advisory data. Until updated, restrict access to the device's web interface with firewall/ACL rules, avoid exposing upload.cgi to the internet, and review device logs for unauthenticated POSTs to upload.cgi. A public PoC exists, so treat internet-facing units as at-risk and verify the device is running the corrected firmware after the vendor releases it.
| Voltronic Power SNMP Web Pro | 1.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
- Weakness
- CWE-434
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.