CVE-2026-12070

Summary

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid through Rollout 524.

Affected Software

VendorProductVersion RangeStatus
Tobit Laboratories AGTeamDavid0 <= Rollout 524affected

Weaknesses

  • CWE-73: CWE-73 External Control of File Name or Path

References