Impact
The flaw arises from the use of a hard‑coded cryptographic key in TeamDavid's Webbox, which stores local user passwords in files that are only obfuscated. When an attacker gains access to the server's filesystem—directly or through another vulnerability such as Random File Read—they can read these files and recover plaintext passwords. The vulnerability affects all TeamDavid releases prior to Rollout 528; from Rollout 528 onward, the problematic functionality is disabled by default and the issue is no longer exposed. This leads to password disclosure and allows attackers to compromise user accounts.
Affected Systems
Tobit Laboratories AG provides the TeamDavid application, specifically its Webbox service. The issue is present in Rollout 528 and affects all installations that store local users’ credentials using this obfuscated method.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity impact, and the EPSS score is less than 1%, indicating a low but nonzero probability of exploitation. Attackers would need local or remote file-system read capabilities, potentially supplied by an additional vulnerability such as Random File Read. Once such access is achieved, the passwords for all local users can be extracted, representing a significant risk to user accounts and the broader environment. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment