Path Traversal Vulnerability in Tobit Laboratories AG TeamDavid's Webbox
CVE-2026-54207
6.3MEDIUM
What is CVE-2026-54207?
The move archive functionality ('!ArcEntryMove') in Tobit Laboratories AG's TeamDavid's Webbox permits the use of arbitrary UNC paths. This lack of validation allows attackers to redirect the server to communicate with malicious SMB servers. Authenticated attackers can exploit this vulnerability to trigger outbound connections to arbitrary endpoints on the SMB protocol, potentially revealing sensitive NTLM authentication information, including NTLM hashes. If outbound connections to SMB port 445 are enabled, this can lead to serious security threats such as SMB relay attacks or credential theft. The exploitation can be done without requiring any authentication, exposing users to additional risks.
Affected Version(s)
TeamDavid 0
