CVE-2026-54200

Tobit Laboratories AG · TeamDavid

Tobit Laboratories AG TeamDavid Webbox contains a local file inclusion vulnerability in the email, fax, and SMS transmission functions.

Executive summary

An authenticated local file inclusion vulnerability in Tobit Laboratories AG TeamDavid allows attackers to access sensitive files on the host system.

Vulnerability

This vulnerability involves improper validation of user-supplied input when processing file paths, allowing an authenticated attacker with low privileges to perform local file inclusion. This flaw resides within the Webbox component of the TeamDavid platform.

Business impact

The ability to perform local file inclusion enables unauthorized access to sensitive configuration files, system data, or credentials stored on the server. Given the CVSS score of 8.4, this vulnerability poses a significant risk to data confidentiality and could facilitate further exploitation of the internal network, potentially resulting in full system compromise.

Remediation

Immediate Action: Update the Tobit Laboratories AG TeamDavid software to a version beyond Rollout 524 as specified in the vendor release notes.

Proactive Monitoring: Monitor server access logs for requests containing directory traversal sequences or attempts to access system files such as /etc/passwd or application configuration files.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common directory traversal patterns and suspicious file path input in URL parameters.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This high-severity vulnerability requires immediate attention to prevent unauthorized system access. Security teams must prioritize updating the affected TeamDavid instance to the latest available version and verify that all system components are patched against this file inclusion flaw.