CRITICAL 9.3 NVD
CVE-2026-44402
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote a
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
References
- https://github.com/Virgula0/CVE-2026-44402
- https://voltronicpower.com/
- https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-unauthenticated-rce-via-
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-04 via NVD.
Risk Timeline
CVE Disclosed2026-09-04 · -1 days ago
Remediation Resources
Analysis & PoC
voltronicpower.com/
vulnfeed aggregates 10236 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.