Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.9%
from disclosure to weapon2 days
Published on NVDSep 4
1st PoC+2d
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Voltronic Power · SNMP Web Propublic PoCs found — 2
cve_referencegithub.com/Virgula0/CVE-2026-44402★ 1githubgithub.com/0xCyp1337/CVE-2026-44402★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.