CVE-2026-54202

EUVD-2026-54434
Tobit Laboratories AG TeamDavid's Webbox  is vulnerable to a path traversal vulnerability in the 
archive creation functionality. Because the archive path is 
user-controlled and insufficiently validated, an attacker can manipulate
 the input to traverse directories. This allows the creation of folders 
in arbitrary locations, including sensitive directories such as 
C:\Windows or for different users. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---