A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded.
https://www.zerodayinitiative.com/advisories/ZDI-21-449/
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01