CVE-2026-22199: Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this vulnerability to disclose sensitive files such as password hashes, which can be cracked offline to obtain root-level access and enable full system compromise.
Security readout for executives and security teams
Plain-English summary
CVE-2026-22199 affects Voltronic Power SNMP Web Pro 1.1. An unauthenticated attacker can abuse a path traversal flaw to read files from the device. The business risk is exposure of sensitive system files, including password hashes, which may enable later full device compromise.
Executive priority
Treat as urgent for any exposed SNMP Web Pro 1.1 device. Prioritize containment of internet-facing management interfaces and vendor guidance review because the flaw requires no login and can disclose credentials useful for deeper compromise.
Technical view
The vulnerability is CWE-22 in the pre-authentication upload.cgi endpoint. The params parameter accepts directory traversal input, allowing arbitrary file read on the device filesystem. The record assigns CVSS 4.0 score 8.7, with network attack vector, low complexity, no privileges, and no user interaction.
Likely exposure
Organizations using Voltronic Power SNMP Web Pro 1.1 are potentially exposed, especially if the web management interface is reachable from untrusted networks. Default status for other versions is unknown in the provided sources.
Exploitation context
The source bundle includes public technical descriptions and a third-party advisory. It is not listed as KEV, and the provided sources do not establish active exploitation in the wild.
Researcher notes
Evidence supports arbitrary file read, not direct code execution for this specific CVE. However, disclosed password hashes may enable offline cracking and root-level access. No patch version is named in the provided sources, so remediation should be guided by vendor or trusted advisory updates.
Mitigation direction
Check Voltronic Power and VulnCheck guidance for fixed versions or vendor-recommended mitigations.
Restrict SNMP Web Pro web management access to trusted administration networks only.
Block internet exposure for affected management interfaces.
Rotate credentials if sensitive files may have been exposed.
Review device access logs for suspicious upload.cgi requests.
Validation and detection
Inventory Voltronic Power SNMP Web Pro deployments and confirm version 1.1 presence.
Determine whether the web interface is reachable from the internet or untrusted networks.
Review logs for upload.cgi requests containing traversal-style input.
Assess whether exposed devices store password hashes or other sensitive local files.
Track vendor advisories for patch availability or configuration guidance.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.