Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion
vulnerability in the send email, fax, SMS, etc. functionality. By
specifying an @@COMMENTFILE command in the form field scjob, any file on
the system can be deleted. This issue affects TeamDavid through Rollout 524.
Published: 2026-08-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

TeamDavid's Webbox contains an input validation flaw that allows a malicious user to delete arbitrary files on the underlying server. By submitting a value for the form field scjob that includes the special @@COMMENTFILE command, the software interprets the parameter as a file deletion instruction, removing any file accessible to the webbox process. The effect is loss of data, potential service disruption, and integrity compromise.

Affected Systems

The vulnerability affects the Tobit Laboratories AG TeamDavid Webbox component released before Rollout 524. Any installation of TeamDavid that uses the send‑email, fax, and SMS features – which rely on the scjob form field – is susceptible. Consequently, older versions of TeamDavid Webbox remain at risk until updated to Rollout 524 or later.

Risk and Exploitability

The CVSS v3.1 score of 8.4 marks this as a high‑severity issue. Because the flaw can be triggered through an HTTP request to the Webbox endpoint, an attacker with network connectivity to the system can craft a request containing a malicious scjob value. Authentication requirements are not detailed in the vendor description; therefore the possibility exists that the endpoint is accessible to authenticated users or, in a worse case, to anonymous traffic. Although EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog, the destructive impact and remote trigger make this problem a high risk to affected deployments.

Generated by OpenCVE AI on August 7, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Tobit Laboratories AG update Rollout 524 or later to remove the vulnerability.
  • Restrict access to the Webbox’s email/fax/SMS services so only authorized administrators can use the scjob form field, using firewalls or authentication controls.
  • If a patch cannot be applied immediately, block or remove the scjob form field and reject any requests that contain the @@COMMENTFILE keyword.

Generated by OpenCVE AI on August 7, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Arbitrary File Deletion via form field 'scjob'
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-08-07T09:40:02.341Z

Reserved: 2026-06-12T09:32:50.925Z

Link: CVE-2026-12070

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T11:12:48Z

Weaknesses
  • CWE-73

    External Control of File Name or Path