CVE-2026-54205Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-07: 2Technical Details · 2026-08-07: 208-07
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locati… https://www.cve.org/CVERecord?id=CVE-2026-54205 ----- Traducción: CVE-2026-54205 Tob… http://infoflow.cloud`

    Post summary

    The tweet references CVE‑2026‑54205, noting a pathname parameter in Tobit Laboratories’ Webbox, but provides no PoC, exploit, patch, or evidence of active use.

    0000032
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54205 Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locati… https://www.cve.org/CVERecord?id=CVE-2026-54205

    Post summary

    The tweet offers a concise technical note on CVE-2026-54205, linking to the official CVE record, but does not provide PoCs, exploits, or mitigation details.

    00000811
    57.9K followersView on X

Explore more