CVE-2026-54204
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox &#39;s search functionality accepts a “pathnameroot” <br />
parameter, which can be set to network locations using UNC paths (e.g., <br />
“\\Server\Share”). The server processes these paths without validation, <br />
resulting in outbound connection attempts to attacker-controlled SMB <br />
servers. This enables unauthenticated attackers to trigger the server to<br />
authenticate to arbitrary SMB endpoints, potentially exposing NTLM <br />
authentication information (such as NTLM hashes). If outbound <br />
connections to port 445 (SMB) are permitted, attackers can use this to <br />
conduct SMB relay or credential theft attacks. Exploitation of the <br />
“pathnameroot” parameter is possible without authentication.<br />
<br />
This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
7.70
Gravedad 4.0
ALTA



