GPU VulnDB

Database/Firmware, BMC & network fabric

Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management card

CVSS 9.3CVE-2026-44402Firmware, BMC & network fabriccurated

Impact

The upload.cgi firmware-update endpoint accepts a tar archive with no credentials, extracts it into a privileged directory and executes its contents as root, giving full control of the UPS network management card. These cards sit on the same management network as BMCs and PDUs and control power to racks, so an attacker who owns one has a persistent foothold on the management VLAN and, depending on how the UPS is wired and configured, influence over power delivery to hardware that is expensive to restart cleanly - GPU nodes mid-training do not survive an unplanned power event gracefully. Firmware on this class of device is rarely re-verified after installation, so an implanted archive tends to survive reboots and is unlikely to be noticed by host-level tooling. Public proof-of-concept code is linked from the record.

Who can reach it

Anyone with network reach to the card's web interface. No authentication and no user interaction - a single crafted POST to upload.cgi. In practice this means anyone on the management VLAN, and anyone on the internet if the card was ever exposed.

What to do

The record names no fixed firmware version and links no vendor advisory - only the researcher advisory and a proof of concept - so treat this as mitigate-only for now. Get these cards off any routed or internet-reachable network immediately, restrict access to a jump host or an ACL that permits only the monitoring system, and check whether upload.cgi can be blocked upstream. Watch the vendor for a firmware release; when one lands, applying it means flashing the management card, which is done with the UPS in service but should be scheduled like any other firmware change on power equipment.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.