Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-44402: Voltronic Power SNMP Web Pro 1.1 allows remote code execution

CVE-2026-44402 · published today
Summary

The firmware‑update feature of Voltronic Power SNMP Web Pro version 1.1 can be tricked into installing a specially crafted file, letting anyone on the network run commands on the device without logging in. This gives an attacker complete control over the equipment, potentially exposing your whole network. Apply the vendor’s update or patch immediately and block external access to the update page until it is fixed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
voltronic power snmp web pro 1.1
Original advisory text
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary command...
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Type
CWE-434Unrestricted File Upload
Timeline
Published4 Sep 2026
Updated4 Sep 2026
First seen4 Sep 2026
Sources
CVE-2026-44402 · MITRE
Monitor software like this
Free during beta