CVE-2026-44402 PUBLISHED

Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi

Assigner: VulnCheck
Reserved: 05.05.2026 Published: 04.09.2026 Updated: 04.09.2026

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Voltronic Power
Product SNMP Web Pro
Versions Default: unaffected
  • Version 1.1 is affected

Credits

  • Angelo Rosa finder

References

Problem Types

  • Unrestricted Upload of File with Dangerous Type CWE