Impact
The vulnerability stems from the use of a hard‑coded cryptographic key in the Webbox component of TeamDavid. User passwords for locally created accounts are stored in various files using only obfuscation rather than proper hashing or encryption. If an attacker can obtain the server’s file system, for instance through a separate “Random File Read” flaw, they can read those obfuscated files and recover the users’ passwords. The flaw allows the disclosure of credential information, compromising confidentiality and potentially enabling further compromise of the affected system.
Affected Systems
Tobit Laboratories AG provides the TeamDavid application, specifically its Webbox service. The issue is present in Rollout 524 and affects all installations that store local users’ credentials using this obfuscated method.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity impact, and although no EPSS score is currently available, the flaw is not listed in the CISA KEV catalog. Attackers would need local or remote file‑system read capabilities, potentially supplied by an additional vulnerability such as Random File Read. Once such access is achieved, the passwords for all local users can be extracted, representing a significant risk to user accounts and the broader environment.
OpenCVE Enrichment