CVE-2026-54208EPSS p30.8%
CVE-2026-54208CVE-2026-54208
Description
Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an
unauthenticated attacker to create or write into existing files on the
server with attacker-controlled content. This is possible because user
input is written directly to files without proper validation or
restriction on file types. As a result, an attacker can create files
(e.g., .htm), containing malicious JavaScript code. When a user accesses
a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid through Rollout 524.
Scoring
| EPSS | 0.38% probability of exploitation · percentile 30.8% · 2026-08-08T12:02:54Z |
| Last modified | 2026-08-07 |