ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply directory traversal sequences via the firmware parameter to access arbitrary files on the server, leading to information disclosure of sensitive system files.
History

Mon, 16 Mar 2026 21:00:00 +0000

Type Values Removed Values Added
Description ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoint. An unauthenticated attacker can supply directory traversal sequences via the firmware parameter to access arbitrary files on the server, leading to information disclosure of sensitive system files.
Title ZwickRoell Test Data Management < 3.0.8 Path Traversal LFI
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-16T20:46:49.771Z

Reserved: 2026-03-04T15:39:26.873Z

Link: CVE-2026-29522

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-16T21:16:33.717

Modified: 2026-03-16T21:16:33.717

Link: CVE-2026-29522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.