Voltronic Power SNMP Web Pro version 1.1 contains a critical unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint. Remote attackers can exploit this flaw without any valid credentials by uploading a specially crafted tar archive to the vulnerable endpoint. The malicious tar archive contains arbitrary executable files that are extracted into a privileged directory on the target system. Once extracted, these files are executed with root privileges, resulting in full system compromise. The vulnerability requires no authentication, significantly lowering the barrier for exploitation. This affects UPS and power management infrastructure, placing it in the critical infrastructure risk category. A proof-of-concept exploit is publicly available on GitHub, increasing the likelihood of active exploitation in the wild.