
I underplayed this one: so I fixed it ! Voltronic Power SNMP Web Pro : CVE-2026-22192 + CVE-2026-22199 / CVSS 10.0 > In a nutshell: Client-side auth bypass, pre-auth path traversal, /etc/shadow, offline crack, SSH root on an industrial UPS. Just another trusted crappy box in the rack becoming the perfect initial access inside the plant(s). 👉Details: https://tinyurl.com/upsremoteroot Kind of things (and way more!) we will talk about during #BSidesOT / ICS #Paris 2026 : Join us ! #OTSecurity #ICS #OffensiveSecurity
Post summary
The post discloses two new CVEs affecting Voltronic Power SNMP Web Pro, detailing authentication bypass and path traversal that allow SSH root access, and links to a page for further technical information.

