Network Security Vulnerability in Tobit Laboratories AG TeamDavid's Webbox
CVE-2026-54204
7.7HIGH
What is CVE-2026-54204?
The search functionality in Tobit Laboratories AG TeamDavid's Webbox is vulnerable due to its improper handling of the 'pathnameroot' parameter. This parameter allows users to specify network locations using UNC paths, which the server processes without appropriate validation. As a result, an unauthenticated attacker can leverage this vulnerability to establish outbound connections to malicious SMB servers, potentially leading to the exposure of sensitive NTLM authentication details, including hashes. Attackers may execute SMB relay or credential theft attacks if outbound connections to port 445 are permitted, heightening the urgency for organizations to secure their installations.
Affected Version(s)
TeamDavid 0
References
CVSS V4
Score:
7.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dario Weiss of InfoGuard Labs
Lucas Dodgson of InfoGuard Labs
