Impact
A path traversal flaw in the archive creation routine of TeamDavid Webbox allows an attacker to craft an archive destination that escapes the intended directory. The server does not properly sanitise or resolve the supplied path, enabling the creation of folders and files in arbitrary locations, including protected directories such as C:\Windows and other users' home spaces. This CWE‑36 weakness can lead to configuration tampering, privilege escalation, or persistence mechanisms by placing malicious files in system or user directories, thereby compromising confidentiality, integrity, and potentially availability of the affected host.
Affected Systems
The vulnerability is confined to Tobit Laboratories AG's TeamDavid Webbox release Rollout 524. Earlier builds are not mentioned as affected, and the issue impacts the archive creation feature exposed through the web interface. Systems running this version should verify their deployment and note that any use of the webbox's archiving capability makes them susceptible.
Risk and Exploitability
The CVSS score of 8.5 marks this as a high‑severity flaw. The EPSS score is currently unavailable, and the vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is through the web interface that accepts archive path input; an attacker can send a crafted request to create directories in sensitive locations. If the webbox runs under elevated privileges or with write access to critical directories, the impact could be significant. The absence of an explicit authentication requirement implies that the path might be exploitable by any user who can interface with the archive creation function, raising the risk to both authenticated and unauthenticated threat actors.
OpenCVE Enrichment