Path Traversal Vulnerability in Tobit Laboratories AG TeamDavid's Webbox
CVE-2026-54207

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54207?

The move archive functionality ('!ArcEntryMove') in Tobit Laboratories AG's TeamDavid's Webbox permits the use of arbitrary UNC paths. This lack of validation allows attackers to redirect the server to communicate with malicious SMB servers. Authenticated attackers can exploit this vulnerability to trigger outbound connections to arbitrary endpoints on the SMB protocol, potentially revealing sensitive NTLM authentication information, including NTLM hashes. If outbound connections to SMB port 445 are enabled, this can lead to serious security threats such as SMB relay attacks or credential theft. The exploitation can be done without requiring any authentication, exposing users to additional risks.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dario Weiss of InfoGuard Labs
.