CVE-2026-54207
Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
07/08/2026
Última modificación:
07/08/2026
Descripción
*** Pendiente de traducción *** Tobit Laboratories AG TeamDavid&#39;s Webbox &#39;s move archive functionality (“!ArcEntryMove”) accepts <br />
an arbitrary path, which can be set to network locations using UNC paths<br />
(e.g., “\\Server\Share”). The server processes these paths without <br />
validation, resulting in outbound connection attempts to <br />
attacker-controlled SMB servers. This enables au-thenticated attackers <br />
to trigger the server to authenticate to arbitrary SMB endpoints, <br />
potentially exposing NTLM authentication information (such as NTLM <br />
hashes). If outbound connections to port 445 (SMB) are permitted, <br />
attackers can use this to conduct SMB relay or credential theft attacks.<br />
Exploitation of the “pathname” parameter is possible without <br />
authentication. This issue affects TeamDavid through Rollout 524.
Impacto
Puntuación base 4.0
6.30
Gravedad 4.0
MEDIA



