ZeroHour

CVE-2026-44402

niche

Unauthenticated RCE in Voltronic Power SNMP Web Pro 1.1

CVSS 4.0
9.3 critical
EPSS
<1%p57
Published
()
Modified
AI analysis

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution flaw (CWE-434) in the upload.cgi firmware update endpoint, which accepts a tar archive without requiring valid credentials. A remote attacker sends a crafted tar archive whose contents are extracted into a privileged directory and executed, giving the attacker arbitrary command execution as root on the device. Successful exploitation results in full compromise of the web management unit, which attackers can then use as a foothold into the surrounding network. Affected users are organizations running SNMP Web Pro 1.1 firmware on Voltronic Power UPS management hardware. Exploitation has not been confirmed in the wild: the flaw is not in CISA KEV, EPSS puts 30-day exploitation probability at 0.9%, but a public proof-of-concept is available on GitHub, so opportunistic scanning is plausible.

What to do: Contact Voltronic Power or your UPS reseller for patched SNMP Web Pro firmware beyond 1.1, as no fixed version is specified in the advisory data. Until updated, restrict access to the device's web interface with firewall/ACL rules, avoid exposing upload.cgi to the internet, and review device logs for unauthenticated POSTs to upload.cgi. A public PoC exists, so treat internet-facing units as at-risk and verify the device is running the corrected firmware after the vendor releases it.

Affected
Voltronic Power SNMP Web Pro1.1
Estimated exposure
nichelikely on the order of thousands of installed management cards, with only hundreds plausibly internet-exposed (estimate; no public scan count in source data) — Voltronic Power's SNMP web management interface is a niche accessory bundled with UPS units rather than mass-market software, and such cards are typically deployed on internal management networks with only a small fraction exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.

Weakness
CWE-434
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.