PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54206 Tobit Laboratories AG CVE debrief

Authenticated attackers can exploit CVE-2026-54206, a medium-severity vulnerability in Tobit Laboratories AG TeamDavid's Webbox, to trigger outbound connections to attacker-controlled SMB servers, potentially exposing NTLM authentication information. The vulnerability affects TeamDavid through Rollout 524 and allows attackers to conduct SMB relay or credential theft attacks if outbound connections to port 445 are permitted. Security teams and administrators should review configurations, conduct regular security audits, and verify outbound connections to port 445.

Vendor
Tobit Laboratories AG
Product
TeamDavid
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-10
Advisory published
2026-08-07
Advisory updated
2026-08-10

Who should care

Security teams and administrators responsible for Tobit Laboratories AG TeamDavid Webbox installations should be aware of this vulnerability and take necessary actions to prevent exploitation. This includes reviewing and updating configurations, conducting regular security audits, and verifying outbound connections to port 445. Additionally, teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Technical summary

The Tobit Laboratories AG TeamDavid Webbox functionality accepts an @@INCLUDE command that can be set to network locations using UNC paths, allowing authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information. The vulnerability affects TeamDavid through Rollout 524 and can be exploited without authentication using the 'pathname' parameter. Attackers can use this to conduct SMB relay or credential theft attacks if outbound connections to port 445 are permitted.

Defensive priority

Authenticated attackers can exploit this vulnerability to conduct SMB relay or credential theft attacks if outbound connections to port 445 are permitted.

Recommended defensive actions

  • Verify and limit outbound connections to port 445
  • Implement compensating controls to monitor and block suspicious SMB connections
  • Review and update TeamDavid Webbox configurations to prevent exploitation
  • Conduct regular security audits and vulnerability assessments
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected product information. The Tobit Laboratories AG TeamDavid Webbox functionality accepts an @@INCLUDE command that can be set to network locations using UNC paths, allowing authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information. The vulnerability affects TeamDavid through Rollout 524. Security teams should verify the affected product deployments in managed environments and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T10:16:57.477Z and has not been modified since then.