{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/voltronic-power/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SNMP Web Pro (1.1)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","cve-2026-44402","firmware-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Voltronic Power"],"content_html":"\u003cp\u003eVoltronic Power SNMP Web Pro 1.1 is susceptible to a critical unauthenticated remote code execution (RCE) vulnerability within the \u003ccode\u003eupload.cgi\u003c/code\u003e endpoint. The vulnerability arises from two primary flaws: the backend fails to validate session cookies, allowing unauthenticated access, and the firmware update functionality accepts and extracts user-supplied tar archives without validation. An attacker can craft a malicious archive containing an \u003ccode\u003einstall.sh\u003c/code\u003e script and a custom CGI file. Once uploaded and triggered via the \u003ccode\u003einstall\u003c/code\u003e parameter, the application executes the malicious script with root privileges, effectively dropping arbitrary CGI files into the web root. This allows for full system compromise on the affected ARM-based Linux device. As of August 12, 2026, no patch is available from the vendor, and public exploit code is available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies the \u003ccode\u003eupload.cgi\u003c/code\u003e endpoint, which does not require valid authentication; any arbitrary session cookie bypasses access controls.\u003c/li\u003e\n\u003cli\u003eThe attacker performs a reconnaissance request to \u003ccode\u003eupload.cgi?params=extract\u003c/code\u003e to confirm file paths and directory expectations via echoed error messages.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious tar archive containing an \u003ccode\u003einstall.sh\u003c/code\u003e script and a backdoor CGI script (e.g., \u003ccode\u003epwned.cgi\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe attacker performs a multipart HTTP POST request to upload the crafted tar archive to the vulnerable server.\u003c/li\u003e\n\u003cli\u003eThe attacker invokes the extraction process via \u003ccode\u003eGET /cgi-bin/upload.cgi?name=upgrade\u0026amp;?params=extract\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the installation process via \u003ccode\u003eGET /cgi-bin/upload.cgi?name=upgrade\u0026amp;?params=install\u003c/code\u003e, which executes the \u003ccode\u003einstall.sh\u003c/code\u003e script as root.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003einstall.sh\u003c/code\u003e script copies the backdoor CGI script into the web server's CGI directory and sets execute permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker executes arbitrary commands by requesting the deployed backdoor CGI script via HTTP, achieving full remote code execution with root privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full system compromise, allowing an attacker to execute arbitrary commands with root privileges on the device. This poses a significant risk to the availability, integrity, and confidentiality of the SNMP-managed power infrastructure. The exploit provides a persistent backdoor by installing a custom CGI handler, enabling ongoing unauthorized access to the underlying ARM Linux environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement an Nginx or similar reverse proxy in front of all Voltronic Power SNMP Web Pro 1.1 instances to enforce strict authentication before reaching the web application.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule below to detect attempts to access the vulnerable \u003ccode\u003eupload.cgi\u003c/code\u003e endpoint with common exploit parameters.\u003c/li\u003e\n\u003cli\u003eMonitor network egress from the SNMP devices to detect unusual activity or shell execution following a POST request to the web interface.\u003c/li\u003e\n\u003cli\u003eBlock or restrict access to the web management interface of SNMP devices from any untrusted or external network segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T13:20:25Z","date_published":"2026-08-12T13:20:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-voltronic-rce/","summary":"Voltronic Power SNMP Web Pro version 1.1 contains an unauthenticated RCE vulnerability allowing attackers to upload and execute malicious CGI scripts as root by bypassing session validation.","title":"Unauthenticated Remote Code Execution in Voltronic Power SNMP Web Pro","url":"https://feed.craftedsignal.io/briefs/2026-08-voltronic-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Voltronic Power","version":"https://jsonfeed.org/version/1.1"}