Impact
The vulnerability exists in the link storing function of Tobit Laboratories AG TeamDavid, where a pathname parameter is interpreted without validation. If set to a UNC path such as \\Server\Share, the server initiates an outbound SMB connection to that location. An attacker can provoke this behavior, and because the server authenticates to the target SMB host, sensitive NTLM credentials may be revealed or transferred via SMB relay tactics. This flaw can be triggered without the need for authentication to the application, meaning any user with network access to the TeamDavid web server could exploit it if they can supply the pathname value.
Affected Systems
Affected systems: Tobit Laboratories AG TeamDavid Webbox installations that include the vulnerable link‑storing feature; all rollouts prior to Rollout 528 (June 30, 2026) are affected, as the functionality remains enabled by default. If the server can reach port 445 on the network, the vulnerability can be exploited. No other vendors or products are affected.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity risk. EPSS is less than 1% (approximately 0.28%), indicating a low but non‑zero probability of exploitation. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed large‑scale exploitation yet. The attack vector relies on SSRF; an unauthenticated attacker can supply the pathname to trick the server into contacting an attacker‑controlled SMB endpoint. If the environment permits outbound SMB traffic, the attacker can capture NTLM hashes or perform a full SMB relay. The flaw is mitigated only by patching the software or restricting outbound SMB traffic from the server.
OpenCVE Enrichment