CVE-2026-54206
Severity CVSS v4.0:
MEDIUM
Type:
CWE-20
Input Validation
Publication date:
07/08/2026
Last modified:
07/09/2026
Description
Tobit Laboratories AG TeamDavid&#39;s Webbox &#39;s sending email, fax, SMS, etc. functionality accepts a <br />
@@INCLUDE command, which can be set to network locations using UNC paths<br />
(e.g., “\\Server\Share”). The server processes these paths without <br />
validation, resulting in outbound connection attempts to <br />
attacker-controlled SMB servers. This enables authenticated attackers to<br />
trigger the server to authenticate to arbitrary SMB endpoints, <br />
potentially exposing NTLM authentication information (such as NTLM <br />
hashes). If outbound connections to port 445 (SMB) are permitted, <br />
attackers can use this to conduct SMB relay or credential theft attacks.<br />
Exploitation of the “pathname” parameter is possible without <br />
authentication. This issue affects TeamDavid before Rollout 528.<br />
<br />
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM


