CVEPublished 2026-08-07Modified 2026-09-070 articles on news4 live referencesNVD data

CVE-2026-54202

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
23
Exploit Prediction Scoring System · top 77% of all CVEs
Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.

Timeline
Published 2026-08-07
Modified 2026-09-07

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-54202 on GitHub.
We haven't classified any articles referencing CVE-2026-54202 yet. The external references above still apply.