CVE-2026-22199: Voltronic Power SNMP Web Pro 1.1 Path Traversal via upload.cgi
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenticated attackers to read arbitrary files on the device filesystem by supplying directory traversal sequences in the params parameter. Attackers can exploit this vulnerability to disclose sensitive files such as password hashes, which can be cracked offline to obtain root-level access and enable full system compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22199?
CVE-2026-22199 is considered a high-severity vulnerability due to its potential impact on comment vote integrity.
How do I fix CVE-2026-22199?
To fix CVE-2026-22199, update wpDiscuz to version 7.6.47 or later.
What specific vulnerability does CVE-2026-22199 describe?
CVE-2026-22199 describes a vote manipulation vulnerability that allows attackers to manipulate comment votes using nonce oracle and IP rotation techniques.
Which versions of wpDiscuz are affected by CVE-2026-22199?
CVE-2026-22199 affects wpDiscuz versions prior to 7.6.47.
What are the consequences of exploiting CVE-2026-22199?
Exploiting CVE-2026-22199 allows attackers to alter comment votes, undermining the trust and integrity of user feedback.