CVE-2026-44402
CRITICAL · 9.8 EPSS 0.9%Automated feed spam dominates; no PoC verification, no KEV, no patching signal yet.
What: Unauthenticated remote code execution in Voltronic Power SNMP Web Pro 1.1 via malicious tar upload to firmware endpoint; CVSS 9.8 (CRITICAL).
Why it matters: High CVSS and claimed public PoC availability drive social signal, but no KEV listing, no confirmed vendor patch, and no defender triage reports yet. Chatter is dominated by automated vulnerability feed reposts from a single aggregator with minimal organic engagement.
Where it's seen: Identical templated posts from vulnerability scanning/aggregation service repeating the same CVE details across Bluesky. No independent researcher PoC confirmation, no vendor advisory linking, no downstream security team questions visible.
RISK: HIGH — Unauthenticated RCE as root on power management systems; exploit claimed but unvalidated.
Description
Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High