ZwickRoell Test Data Management Local File Inclusion Vulnerability
Vulnerability
A local file inclusion vulnerability has been identified in ZwickRoell Test Data Management versions prior to 3.0.8. The issue resides in the /server/node_upgrade_srv.js endpoint, where an unauthenticated attacker can exploit directory traversal sequences via the firmware parameter. This exploitation allows access to arbitrary files on the server, potentially disclosing sensitive system information.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive system files on the server.
Added: Mar 16, 2026, 9:19 PM
Updated: Mar 16, 2026, 9:19 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
3.3exploitability
7.4remediation
0.0relevance
4.0threat
0.0urgency
2.9incentive
4.2Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
