CVE-2026-54202
Received Received - Intake

Path Traversal in Tobit TeamDavid's Webbox

Vulnerability report for CVE-2026-54202, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users.Β This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-36 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TeamDavid's Webbox has a path traversal vulnerability in its archive creation feature. The vulnerability occurs because user-controlled input is used to determine the archive path without proper validation. This allows attackers to manipulate the input to traverse directories and create folders in arbitrary locations, including sensitive system directories like C:\Windows or user-specific folders.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized directory creation or suspicious archive operations in TeamDavid's Webbox. Monitor logs for unusual paths or files created outside expected directories. Check for folders like C:\Windows or user-specific directories created unexpectedly.

Impact Analysis

An attacker could exploit this to place malicious files in critical system directories, potentially leading to system compromise, unauthorized code execution, or disruption of services. It may also allow access to sensitive user data if folders are created in user-specific locations.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties or reputational damage.

Mitigation Strategies

Immediately update TeamDavid to a version beyond Rollout 524 to address the path traversal issue. Restrict user permissions to prevent unauthorized directory creation. Review and remove any suspicious folders or files created in sensitive locations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54202. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart