Network Security Vulnerability in Tobit Laboratories AG TeamDavid's Webbox
CVE-2026-54204

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54204?

The search functionality in Tobit Laboratories AG TeamDavid's Webbox is vulnerable due to its improper handling of the 'pathnameroot' parameter. This parameter allows users to specify network locations using UNC paths, which the server processes without appropriate validation. As a result, an unauthenticated attacker can leverage this vulnerability to establish outbound connections to malicious SMB servers, potentially leading to the exposure of sensitive NTLM authentication details, including hashes. Attackers may execute SMB relay or credential theft attacks if outbound connections to port 445 are permitted, heightening the urgency for organizations to secure their installations.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
Lucas Dodgson of InfoGuard Labs
.