Impact
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution flaw in its upload.cgi firmware update endpoint. A remote attacker can upload a crafted tar archive that includes executable files; these files are extracted to a privileged directory and executed as root, giving the attacker full control of the system. This issue is a classic example of improper file upload validation, classified as CWE‑434.
Affected Systems
The vulnerability affects Voltronic Power SNMP Web Pro version 1.1. Any instance of this firmware exposed to a network with the upload.cgi endpoint enabled can be compromised without authentication.
Risk and Exploitability
The CVSS score of 9.3 denotes critical severity. Although no exploitation probability metric is publicly available, the capability to run arbitrary code as root without credentials represents a high‑risk situation. The attack vector is remote over the network, achieved by sending a malicious tar file to the upload.cgi endpoint.
OpenCVE Enrichment