Database/Firmware, BMC & network fabric
Voltronic Power SNMP Web Pro: unauthenticated firmware upload yields root on the UPS management card
Impact
The upload.cgi firmware-update endpoint accepts a tar archive with no credentials, extracts it into a privileged directory and executes its contents as root, giving full control of the UPS network management card. These cards sit on the same management network as BMCs and PDUs and control power to racks, so an attacker who owns one has a persistent foothold on the management VLAN and, depending on how the UPS is wired and configured, influence over power delivery to hardware that is expensive to restart cleanly - GPU nodes mid-training do not survive an unplanned power event gracefully. Firmware on this class of device is rarely re-verified after installation, so an implanted archive tends to survive reboots and is unlikely to be noticed by host-level tooling. Public proof-of-concept code is linked from the record.
Who can reach it
Anyone with network reach to the card's web interface. No authentication and no user interaction - a single crafted POST to upload.cgi. In practice this means anyone on the management VLAN, and anyone on the internet if the card was ever exposed.
What to do
The record names no fixed firmware version and links no vendor advisory - only the researcher advisory and a proof of concept - so treat this as mitigate-only for now. Get these cards off any routed or internet-reachable network immediately, restrict access to a jump host or an ACL that permits only the monitoring system, and check whether upload.cgi can be blocked upstream. Watch the vendor for a firmware release; when one lands, applying it means flashing the management card, which is done with the UPS in service but should be scheduled like any other firmware change on power equipment.
References
Related entries
- fakefish: KubeVirt backend ignores Redfish credentials, exposing VM power and virtual mediaCVE-2026-71566 · fakefish (Redfish BMC shim, KubeVirt backend)Critical
- Linux kernel (drivers/infiniband/hw/bnxt_re): A user context could request the write-combine doorbell page repeatedlyCVE-2026-72495 · Linux kernel (drivers/infiniband/hw/bnxt_re)Critical
- Phison PS3111-S11 SSD firmware: signature check trusts a modulus carried in the image, so any firmware verifiesCVE-2026-82876 · Phison PS3111-S11 SSD controller firmware (signature verification root of trust)Critical
- Phison PS3111-S11 SSD firmware: vendor unique commands allow persistent implants in controller flashCVE-2026-84696 · Phison PS3111-S11 SSD controller firmware (vendor unique commands over ATA)Critical
- Tripp Lite PDUMH15AT / SU750XL PDU: The PDU accepts unauthenticated POST requests to its /Forms/ endpoints, which canCVE-2019-16261 · Tripp Lite PDUMH15AT / SU750XL PDUCritical
- IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handling: The original default BMC password kept workingCVE-2019-4169 · IBM OpenPower firmware OP910/OP920 - OpenBMC IPMI credential handlingCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.