Description
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
Published: 2026-09-04
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution flaw in its upload.cgi firmware update endpoint. A remote attacker can upload a crafted tar archive that includes executable files; these files are extracted to a privileged directory and executed as root, giving the attacker full control of the system. This issue is a classic example of improper file upload validation, classified as CWE‑434.

Affected Systems

The vulnerability affects Voltronic Power SNMP Web Pro version 1.1. Any instance of this firmware exposed to a network with the upload.cgi endpoint enabled can be compromised without authentication.

Risk and Exploitability

The CVSS score of 9.3 denotes critical severity. Although no exploitation probability metric is publicly available, the capability to run arbitrary code as root without credentials represents a high‑risk situation. The attack vector is remote over the network, achieved by sending a malicious tar file to the upload.cgi endpoint.

Generated by OpenCVE AI on September 4, 2026 at 16:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Voltronic Power SNMP Web Pro to the latest firmware version that includes the upload.cgi fix if one is available.
  • If no update is available, disable or lock down the upload.cgi endpoint by configuring firewall rules or device access controls so that only trusted sources can reach it.
  • If the service is not required, disable the SNMP Web Pro service or place the device behind network segmentation to isolate it from untrusted networks.

Generated by OpenCVE AI on September 4, 2026 at 16:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Voltronicpower
Voltronicpower snmp Web Pro
Vendors & Products Voltronicpower
Voltronicpower snmp Web Pro

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
Title Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Voltronicpower Snmp Web Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-04T17:40:02.300Z

Reserved: 2026-05-05T21:38:43.137Z

Link: CVE-2026-44402

cve-icon Vulnrichment

Updated: 2026-09-04T17:39:58.524Z

cve-icon NVD

Status : Received

Published: 2026-09-04T16:17:25.250

Modified: 2026-09-04T18:17:52.080

Link: CVE-2026-44402

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T17:00:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type