Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54218

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-321 Uso de claves de cifrado embebidas en el software
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid&amp;#39;s Webbox. For users created locally in David, passwords are stored in various <br /> files using only obfuscation. Any user with access to the server’s file <br /> system, or who can otherwise extract files from the server (see <br /> vulnerability “Random File Read”), can potentially obtain affected <br /> users’ passwords. This issue affects TeamDavid through Rollout 524.