Path traversal vulnerability in the file upload functionality allows overwriting of any file on the device.

CWE: CWE-20:Improper Input Validation