Impact
The vulnerability exists in Tobit Laboratories AG TeamDavid’s Webbox move archive functionality, where the '!ArcEntryMove' endpoint accepts any string for the 'pathname' parameter. An attacker can supply a UNC path such as '\\Server\\Share', which the server resolves without validation and attempts to connect to over SMB (port 445). This behavior allows an attacker to invoke the server’s outbound SMB authentication, potentially leaking NTLM hash credentials. Because this mechanism can be invoked without prior authentication, it may enable an unauthenticated attacker to collect credential material or facilitate SMB relay attacks.
Affected Systems
Affected product is Tobit Laboratories AG TeamDavid Webbox, version Rollout 524 and earlier. The issue was identified in all releases up to Rollout 524. The vulnerability impacts systems running TeamDavid on any network where outbound SMB traffic is allowed, and where the move archive feature is enabled.
Risk and Exploitability
With a CVSS score of 6.3 the vulnerability is classified as moderate severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack requires the server to have outbound access to TCP/445; if this connection is blocked, exploitation is constrained. Nonetheless, unauthenticated usage of the endpoint makes the vulnerability reachable without user action. Successful exploitation could lead to credential theft and possible SMB relay attacks, which may facilitate lateral movement within the target environment.
OpenCVE Enrichment