SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-44402

CRITICAL · CVSS 9.8 EPSS 0.89% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Voltronic Power SNMP Web Pro 1.1 is vulnerable to an unauthenticated remote code execution flaw in the upload.cgi firmware update endpoint, enabling attackers to execute arbitrary commands with root privileges by uploading a specially crafted tar archive. This critical vulnerability poses a severe risk of full system compromise, making it essential for organizations using this product to prioritize immediate remediation efforts. All users of the affected software should assess their exposure and apply necessary security measures to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44402
Severity
CRITICAL
CVSS
9.8
EPSS
0.89%

Original NVD Description

Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers can supply a malicious tar archive containing arbitrary executable files that are extracted to a privileged directory and executed as root, achieving full system compromise.