Impact
Tobit Laboratories AG’s TeamDavid Webbox email, fax, SMS, and other sending functions accept a UNC path specification through the pathname parameter. The server processes these paths without validation, causing outbound SMB connections to addresses supplied by an attacker. This vulnerability corresponds to the CWE‑918 Server‑Side Request Forgery and the broader CWE‑20 Improper Input Validation weakness. An attacker exploiting the share path can force the Webbox to authenticate to an arbitrary SMB endpoint and capture the NTLM hash or relay the request, enabling credential theft or further lateral movement. The impact therefore spans confidentiality compromise of network credentials rather than arbitrary code execution.
Affected Systems
The affected product is Tobit Laboratories AG’s TeamDavid, specifically the Webbox component in Rollout 524 and earlier releases.
Risk and Exploitability
The CVSS score is 6.3, indicating a moderate severity. No EPSS score is publicly available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s KEV catalog. It can be triggered without authentication, so any user or attacker who can reach the Webbox’s HTTP endpoint can abuse it, provided that outbound connections to port 445 are permitted on the network. The risk is heightened where the Webbox can reach internal SMB servers or where attackers can relay “Nego” or “NTLM” challenges to steal credentials.
OpenCVE Enrichment