Junglewise Threat Intelligence

CVE-2026-44402: Voltronic Power SNMP Web Pro unauthenticated remote code execution

CVE-2026-44402 · Severity: critical · CVSS 9.8 · Published 2026-09-04

Executive brief

Voltronic Power SNMP Web Pro is a network management interface used to monitor and control UPS and power systems. An unauthenticated attacker can exploit a flaw in the firmware upload endpoint to execute arbitrary commands with root privileges, achieving complete control over the affected device and any systems it protects.

Technical details

The vulnerability is an unauthenticated remote code execution flaw in the upload.cgi firmware update endpoint. An attacker can craft a malicious tar archive and submit it to the vulnerable endpoint without providing valid credentials. When processed, the tar archive is extracted to a privileged directory and its contents are executed as root, allowing arbitrary command execution. The attack requires only network access to the web interface and no authentication. Full system compromise is achievable.

Affected products

  • Voltronic Power SNMP Web Pro 1.1

Timeline

  • 2026-09-04: disclosed

References