Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54202

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to a path traversal vulnerability in the <br /> archive creation functionality. Because the archive path is <br /> user-controlled and insufficiently validated, an attacker can manipulate<br /> the input to traverse directories. This allows the creation of folders <br /> in arbitrary locations, including sensitive directories such as <br /> C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.