Security Advisory

CVE-2026-54202

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-07 09:43:41
Last updated 2026-08-07 09:43:41
Assigner NCSC.ch
CVSS score not scored
State PUBLISHED

Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.