What is CVE-2026-54205?
CVE-2026-54205 is a Server-Side Request Forgery (SSRF) vulnerability in Tobit Laboratories AG's TeamDavid Webbox link storing functionality. The 'pathname' parameter accepts UNC paths without validation, allowing unauthenticated attackers to force outbound connections. Affected systems should restrict the 'pathname' parameter to prevent exploitation.
Azərbaycanca: CVE-2026-54205 zəifliyi Tobit Laboratories AG-nin TeamDavid Webbox məhsulunda link saxlama funksionallığında aşkarlanıb. 'pathname' parametri vasitəsilə UNC yol qəbul edilir və server tərəfindən yoxlanılmadan işlənir, bu da autentifikasiya olunmamış SSRF hücumlarına səbəb ola bilər. Təsirə məruz qalan sistemlərdə daxil olan 'pathname' dəyərləri dərhal məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Tobit Laboratories AG
FAQ2
Which functionality of TeamDavid Webbox is affected by CVE-2026-54205?
This vulnerability affects the link storing functionality of TeamDavid Webbox.
Which parameter is processed without validation in CVE-2026-54205?
The 'pathname' parameter is processed without validation by the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.