Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54200

Gravedad CVSS v4.0:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox is vulnerable to a local file inclusion vulnerability in<br /> the send email, fax, SMS, etc. functionality. By specifying an &amp;#39;@@attach&amp;#39; command in the form field &amp;#39;scjob&amp;#39;, files can be attached to a message, <br /> which can then be downloaded by an authenticated user. A filter is in <br /> place that restricts access to the David con-fig folder and the user <br /> folder. However, this filter can be bypassed by specifying an alternate <br /> data stream, allowing the download of sensitive files such as other <br /> users&amp;#39; access files containing their passwords or the server&amp;#39;s private <br /> key. This issue affects TeamDavid through Rollout 524.