CVE-2026-54202EPSS p22.6%
CVE-2026-54202CVE-2026-54202
Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the
archive creation functionality. Because the archive path is
user-controlled and insufficiently validated, an attacker can manipulate
the input to traverse directories. This allows the creation of folders
in arbitrary locations, including sensitive directories such as
C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.
Scoring
| EPSS | 0.30% probability of exploitation · percentile 22.6% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |