CVE-2026-54205 Details
Description
Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
A server-side request forgery (SSRF) vulnerability has been identified in Tobit Laboratories AG TeamDavid's Webbox application, specifically in the link storing functionality. The vulnerability arises because the application accepts UNC paths in the 'pathname' parameter without proper validation, allowing authenticated attackers to direct the server to connect to malicious SMB servers. This could lead to the interception of NTLM authentication data, such as NTLM hashes, or facilitate SMB relay attacks, particularly if the server is allowed to make outbound connections to port 445.
Users are advised to update to the latest version of TeamDavid, as the most recent release appears to address this vulnerability. Additionally, organizations should restrict outbound SMB traffic on port 445 and consider placing the TeamDavid web server behind a VPN or reverse proxy that filters requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | CISA-ADP | BundleRemedyTechnical Analysis |
| https://chayns.net/77892-10814/tapp/763210?postId=11454 | [email protected] | |
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | [email protected] | BundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tobit Laboratories AG TeamDavid | <= 524 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion