Voltronicpower develops a narrow range of power-management and monitoring software, particularly ViewPower and SNMP Web Pro, that serve critical infrastructure and data-center environments where uptime and remote manageability are paramount. Despite a compact product portfolio, the vendor occupies a prominent position in vulnerability discourse due to a strong concentration of critical-severity flaws that reflect systemic weaknesses in access control and input handling. The recurring vulnerability patterns—exposed dangerous methods, untrusted deserialization, OS command injection, SQL injection, and missing authentication on critical functions—point to a consistent pattern of insufficient isolation between administrative and user-facing interfaces, a structural risk in software managing physical infrastructure. Defenders operating power-management or SNMP monitoring infrastructure should treat this vendor's advisories as high-priority and apply patches to isolated or air-gapped environments where feasible, since these products often sit in sensitive operational networks. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Voltronicpower over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51595CRITICAL Voltronic Power ViewPower Pro selectDeviceListBy SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | May 3, 2024 | 9.8 | 52 | NO | NO |
CVE-2023-51573CRITICAL Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authenticat | Apr 1, 2024 | 9.8 | 52 | NO | NO |
CVE-2023-51572CRITICAL Voltronic Power ViewPower Pro getMacAddressByIp Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affec | Apr 1, 2024 | 9.8 | 52 | NO | NO |
CVE-2023-51587HIGH Voltronic Power ViewPower getModbusPassword Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio | May 3, 2024 | 7.5 | 37 | NO | NO |
CVE-2023-51581CRITICAL Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af | May 3, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-39073CRITICAL An issue in SNMP Web Pro v.1.1 allows a remote attacker to execute arbitrary code and obtain senstive information via a crafted request. | Sep 12, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-33274CRITICAL The authentication mechanism in PowerShield SNMP Web Pro 1.1 contains a vulnerability that allows unauthenticated users to directly access Common Gateway Interface (CGI) scripts wi | Jul 12, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-51593CRITICAL Voltronic Power ViewPower Pro Expression Language Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | May 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51590CRITICAL Voltronic Power ViewPower Pro UpLoadAction Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff | May 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51586CRITICAL Voltronic Power ViewPower Pro selectEventConfig SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected | May 3, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Voltronicpower.
Media articles that mention a CVE ID that affects a product developed by Voltronicpower — matched by CVE ID, not by vendor name.