Vulnerability Description
Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localStorage values. Attackers can modify client-side authentication state to bypass server-side access controls and gain unauthorized access to protected management functionality without valid credentials.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gvectors | Wpdiscuz | < 7.6.47 |
Related Weaknesses (CWE)
References
- https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22192-22199_Voltronic
- https://voltronicpower.com/
- https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/
- https://www.vulncheck.com/advisories/voltronic-power-snmp-web-pro-authentication
FAQ
What is CVE-2026-22192?
CVE-2026-22192 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Voltronic Power SNMP Web Pro version 1.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to access privileged management functions by manipulating browser localSt...
How severe is CVE-2026-22192?
CVE-2026-22192 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-22192?
Check the references section above for vendor advisories and patch information. Affected products include: Gvectors Wpdiscuz.