PatchSiren

Tobit Laboratories AG CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-54206

Authenticated attackers can exploit CVE-2026-54206, a medium-severity vulnerability in Tobit Laboratories AG TeamDavid's Webbox, to trigger outbound connections to attacker-controlled SMB servers, potentially exposing NTLM authentication information. The vulnerability affects TeamDavid through Rollout 524 and allows attackers to conduct SMB relay or credential theft attacks if outbound connections to port [truncated]

HIGH Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-54202

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2026-54202 is a path traversal vulnerability in Tobit Laboratories AG TeamDavid's Webbox. The vulnerability allows attackers to manipulate archive paths, potentially leading to the creation of folders in arbitrary locations, including sensitive directories such as C:Windows or for different users. This issue affects TeamDavid through [truncated]

HIGH Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-54200

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T10:16:56.640Z and has not been modified since then. Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, wh [truncated]

MEDIUM Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-54199

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. The vulnerability allows an attacker to control the response headers by adding a line feed to the redirect link. This issue affects TeamDavid through Rollout 5 [truncated]

MEDIUM Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-12071

The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, which can be manipulated to redirect users to malicious domains. This vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. A similar, registerable TLD can be used by an attacker to craft a URL to redirect users to a malicious domain. The issue affects TeamDavid through Rollout 524. E [truncated]

HIGH Tobit Laboratories AG CVE published 2026-08-07

CVE-2026-12070

CVE-2026-12070 affects Tobit Laboratories AG TeamDavid's Webbox, introducing an arbitrary file deletion vulnerability through the send email, fax, SMS functionality. The vulnerability can be exploited by specifying an @@COMMENTFILE command in the form field scjob, enabling any file on the system to be deleted. This issue affects TeamDavid through Rollout 524. Organizations should verify and apply the vend [truncated]