๐Ÿ” CVE Alert

CVE-2026-22199

HIGH 7.5

Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
12th

Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this vulnerability to disclose sensitive files such as password hashes, which can be cracked offline to obtain root-level access and enable full system compromise.

CWE CWE-22
Vendor voltronic power
Product snmp web pro
Published Mar 13, 2026
Last Updated Apr 23, 2026
Stay Ahead of the Next One

Get instant alerts for voltronic power snmp web pro

Be the first to know when new high vulnerabilities affecting voltronic power snmp web pro are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Voltronic Power / SNMP Web Pro
1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22192-22199_Voltronic-Power_Preauth_root_RCE.txt boffsec-services.com: https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ voltronicpower.com: https://voltronicpower.com/ vulncheck.com: https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-path-traversal-via-upload-cgi

Credits

Jean-Marie Bourbon of Bourbon Offensive Security Services VulnCheck