Tobit Laboratories AG TeamDavid's Webbox Vulnerability in Network Communication
CVE-2026-54206

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54206?

A vulnerability exists in Tobit Laboratories AG's TeamDavid's Webbox allowing authenticated attackers to exploit the application's mail, fax, and SMS functionalities through an insecure command input. This involves the use of the @@INCLUDE command that accepts UNC path specifications, leading the server to initiate outbound connections to potentially malicious SMB servers. Such behavior, coupled with the application's failure to validate these paths, puts sensitive NTLM authentication information at risk. If the server is permitted to connect over port 445, attackers could exploit this to carry out SMB relay or credential theft attacks, compromising the security of the affected systems.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.