Vulnerabilities
Products Security index
Vulnerabilities
CVE-2026-44402
Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi
CVE-2026-22199
Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
CVE-2026-22192
Voltronic Power SNMP Web Pro 1.1 Authentication Bypass via localStorage
CVE-2025-65287
An unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary files. The CGI concatenates the user-supplied params directly onto the base path (/var/www/files/userScript/) using memcpy + strcat without validation or canonicalization, enabling ../ sequences to escape the intended directory. The download branch also echoes the unsanitized params into Content-Disposition, introducing header-injection risk.
CVE-2022-31491
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code immediately regardless of any managed UPS state or presence.
