CVE-2026-54206
Received Received - Intake

NTLM Hash Exposure via SMB Relay in TeamDavid Webbox

Vulnerability report for CVE-2026-54206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Tobit Laboratories AG TeamDavid's Webbox 's sending email, fax, SMS, etc. functionality accepts a @@INCLUDE command, which can be set to network locations using UNC paths (e.g., β€œ\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the β€œpathname” parameter is possible without authentication.Β This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TeamDavid's Webbox has a flaw in its email, fax, SMS, and similar functionality where it accepts an @@INCLUDE command with UNC paths (e.g., \Server\Share). The server processes these paths without validation, leading to outbound connections to attacker-controlled SMB servers. This allows attackers to trigger authentication attempts to arbitrary SMB endpoints, potentially exposing NTLM authentication details like hashes. Exploitation is possible without authentication.

Detection Guidance

To detect this vulnerability, monitor outbound SMB connections (port 445) from TeamDavid's Webbox. Check logs for UNC path processing attempts or unexpected authentication requests to external servers. Use network sniffing tools like Wireshark to capture SMB traffic initiated by the application.

Impact Analysis

This vulnerability can expose NTLM authentication credentials (such as hashes) to attackers. If outbound SMB connections are allowed, attackers may perform SMB relay attacks or steal credentials. Unauthenticated attackers can exploit this to trigger server connections to malicious SMB servers, compromising sensitive authentication data.

Compliance Impact

This vulnerability could expose NTLM authentication information, which may lead to credential theft. For GDPR, unauthorized access to personal data via credential theft could violate data protection principles. For HIPAA, compromised credentials might enable unauthorized access to protected health information, risking compliance with security requirements.

Mitigation Strategies

Immediately update TeamDavid to the latest Rollout version beyond 524. Block outbound SMB traffic (port 445) at the firewall. Disable UNC path processing in TeamDavid's configuration. Monitor for unauthorized authentication attempts and restrict SMB relay capabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54206. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart