CVE-2026-54204
Tobit Laboratories AG · TeamDavid
Tobit TeamDavid Webbox contains a Server-Side Request Forgery vulnerability in the search functionality, allowing unauthenticated attackers to supply UNC paths via the pathnameroot parameter.
Executive summary
A Server-Side Request Forgery vulnerability in Tobit TeamDavid Webbox allows unauthenticated remote attackers to perform unauthorized requests using UNC paths.
Vulnerability
The application fails to validate the pathnameroot parameter in the Webbox search function, which enables an unauthenticated attacker to force the server to interact with arbitrary network locations via UNC paths.
Business impact
The vulnerability carries a CVSS score of 7.7, indicating high severity. Exploitation could allow attackers to bypass network perimeters, potentially leading to information disclosure or internal network mapping. This poses a significant risk to organizational confidentiality and infrastructure integrity.
Remediation
Immediate Action: Update to the latest available version of TeamDavid beyond Rollout 524 as specified in the vendor release notes.
Proactive Monitoring: Inspect network traffic for unusual SMB or UNC-related connection attempts originating from the TeamDavid server.
Compensating Controls: Implement strict egress filtering on the host to prevent unauthorized outbound connections to external or untrusted internal network segments.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for network-level exploitation, organizations running Tobit TeamDavid should prioritize updating their software immediately. Ensure that the server environment is isolated from sensitive internal resources if a patch cannot be deployed instantly.