Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-54204

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-20 Validación incorrecta de entrada
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026

Descripción

*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&amp;#39;s Webbox &amp;#39;s search functionality accepts a “pathnameroot” <br /> parameter, which can be set to network locations using UNC paths (e.g., <br /> “\\Server\Share”). The server processes these paths without validation, <br /> resulting in outbound connection attempts to attacker-controlled SMB <br /> servers. This enables unauthenticated attackers to trigger the server to<br /> authenticate to arbitrary SMB endpoints, potentially exposing NTLM <br /> authentication information (such as NTLM hashes). If outbound <br /> connections to port 445 (SMB) are permitted, attackers can use this to <br /> conduct SMB relay or credential theft attacks. Exploitation of the <br /> “pathnameroot” parameter is possible without authentication.<br /> <br /> This issue affects TeamDavid through Rollout 524.