---
id: CVE-2026-44402
title: >-
  Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code
  execution vulnerability in the upload.cgi firmware update endpoint that allows
  remote attackers to execute arbitrary commands as root by uploading a crafted
  tar arc…
summary: >-
  Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code
  execution vulnerability in the upload.cgi firmware update endpoint that allows
  remote attackers to execute arbitrary commands as root by uploading a crafted
  tar arc…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: Voltronic Power
product: SNMP Web Pro
affected:
  - snmp_web_pro 1.1
published: '2026-09-04'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-44402'
references:
  - url: 'https://github.com/Virgula0/CVE-2026-44402'
    label: disclosure@vulncheck.com
  - url: 'https://voltronicpower.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-unauthenticated-rce-via-upload-cgi
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-04T17:39:52.858365Z'
ingestedAt: '2026-09-14T13:52:27.070Z'
epss: 0.01317
epssPercentile: 0.69545
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/Virgula0/CVE-2026-44402'
    - 'https://github.com/0xCyp1337/CVE-2026-44402'
  checkedAt: '2026-09-25T08:20:57.616Z'
---

## Overview

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
