Voltronicpower Snmp Web Pro
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Voltronicpower Snmp Web Pro.
By the Year
In 2026 there have been 2 vulnerabilities in Voltronicpower Snmp Web Pro with an average score of 8.7 out of ten. Snmp Web Pro did not have any published security vulnerabilities last year. That is, 2 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 8.70 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 3 | 8.57 |
It may take a day or so for new Snmp Web Pro vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Voltronicpower Snmp Web Pro Security Vulnerabilities
wpDiscuz <7.6.47 vote manipulation via nonce reuse & header spoof
CVE-2026-22199
7.5 - High
- March 13, 2026
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this vulnerability to disclose sensitive files such as password hashes, which can be cracked offline to obtain root-level access and enable full system compromise.
Directory traversal
wpDiscuz <7.6.47 Stored XSS via customCss in options import
CVE-2026-22192
9.9 - Critical
- March 13, 2026
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.
Missing Authentication for Critical Function
Voltronic Power SNMP Web Pro 1.1 XSS allows arbitrary code exec
CVE-2023-49563
6.1 - Medium
- December 12, 2023
Cross Site Scripting (XSS) in Voltronic Power SNMP Web Pro v.1.1 allows an attacker to execute arbitrary code via a crafted script within a request to the webserver.
XSS
Remote Code Exec in SNMP Web Pro v1.1 via Crafted SNMP Request
CVE-2023-39073
9.8 - Critical
- September 12, 2023
An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request.
AuthZ
Unauthenticated Access to CGI in PowerShield SNMP Web Pro 1.1
CVE-2023-33274
9.8 - Critical
- July 12, 2023
The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts without proper identification or authorization. This vulnerability arises from a lack of proper cookie verification and affects all instances of SNMP Web Pro 1.1 without HTTP Digest authentication enabled, regardless of the password used for the web interface.
authentification
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Voltronicpower Snmp Web Pro or by Voltronicpower? Click the Watch button to subscribe.