Path Traversal Vulnerability in Tobit Laboratories AG TeamDavid's Webbox
CVE-2026-54202

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54202?

Tobit Laboratories AG TeamDavid's Webbox is susceptible to a path traversal vulnerability in its archive creation functionality. The vulnerability arises from user-controlled input for the archive path, which is not adequately validated. This flaw permits an attacker to manipulate input to navigate through directories, potentially allowing the creation of folders in sensitive locations such as C:\Windows or in user directories. Affected version: Rollout 524.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.