Voltronic Power SNMP Web Pro 1.1 存在一个未认证的远程代码执行漏洞,位于 固件更新端点。攻击者无需有效凭证,只需上传一个构造的 tar 归档文件,即可在系统上以 root 权限执行任意命令。攻击者可以提交一个包含任意可执行文件的恶意 tar 归档,这些文件会被解压到具有特权的目录中,并以 root 身份执行,从而实现对系统的完全控制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Voltronic Power | SNMP Web Pro | 1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Voltronic Power | SNMP Web Pro | 1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet