HarborGuard / CVE
Back to search
HIGHCVE-2026-29522Published Modified CNA VulnCheck

CVE-2026-29522: ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI

ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply directory traversal sequences via the firmware parameter to access arbitrary files on the server, leading to information disclosure of sensitive system files.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
3.0.8
Affected Products
1

Fix available

3.0.8
Affected packages
  • ZwickRoell GmbH & Co. KG / Test Data Management
    < 3.0.8 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVE-2026-29522: ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI | HarborGuard CVE