CVE-2026-54206

Severity CVSS v4.0:
MEDIUM
Type:
CWE-20 Input Validation
Publication date:
07/08/2026
Last modified:
07/09/2026

Description

Tobit Laboratories AG TeamDavid&amp;#39;s Webbox &amp;#39;s sending email, fax, SMS, etc. functionality accepts a <br /> @@INCLUDE command, which can be set to network locations using UNC paths<br /> (e.g., “\\Server\Share”). The server processes these paths without <br /> validation, resulting in outbound connection attempts to <br /> attacker-controlled SMB servers. This enables authenticated attackers to<br /> trigger the server to authenticate to arbitrary SMB endpoints, <br /> potentially exposing NTLM authentication information (such as NTLM <br /> hashes). If outbound connections to port 445 (SMB) are permitted, <br /> attackers can use this to conduct SMB relay or credential theft attacks.<br /> Exploitation of the “pathname” parameter is possible without <br /> authentication. This issue affects TeamDavid before Rollout 528.<br /> <br /> Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.